[Uta] Re: webpki anchors and comodo-gate-style attacks

2025-03-07 Thread Rob Stradling
The CABForum TLS BRs don't suggest a name for this AFAICT. The nearest I can find is: "Application Software Supplier: A supplier of Internet browser software or other relying‐party application software that displays or uses Certificates and incorporates Root Certificates." Despite having non-

[Uta] Re: webpki anchors and comodo-gate-style attacks

2025-03-04 Thread Rob Stradling
> 2. An attack where CA B (mistakenly) issues a certificate for corp.example, > when it should have been CA A is called... ??? > I know it as Comodo-Gate. (Your question almost identified an answer 😉 ) CAA (RFC6844, obsoleted by RFC8659), which was one good thing that came out of the Comodo-gate