5 ms·
It's signed by the DoD CA.
by blcknight 10y ago
It's signed by the DoD CA.
- perlgeek 10y agoMaybe they should get their CA cross-signed by one that's in all major browsers.
- dogma1138 10y agoArguably there would be quite a few people who object to the DoD getting their CA's into browsers this isn't a good precedent. DoD today, UK MOD tomorrow, Russia and China when?
- MichaelGG 10y agoWhat's the problem? Sounds like a good idea. If they ever abuse their status they get revoked, causing them a lot of pain. More pain than if they hadn't been depending on being trusted in the first place.
- dogma1138 10y agoRevoking CA's is considerably harder than you think it might work for you but it might not work for the tons of people that do not update their browsers or operating systems. Private/Internal/Enterprise CA's are intentionally out of the ring of trust for SSL certificates, there is no need to give the DoD any preferential treatment. This would literally benefit no one as anyone with any interest in accessing those websites would install the certificate. US .gov sites are "secured" with commercial CA certificates so they aren't even part of the argument. When you count the benefit / usefulness of this change which is very little to null and compare it to the possibility of it being abused as well as the precedent of adding "internal" certificate authorities to the global trust list I see a pretty solid argument against this. Overall with things like LetsEncrypt I hope that the CA/SSL Cert industry would get disrupted enough for most if not all commercial CA's to simply become irrelevant. It's not a question of insurance rather than a technical issue since you still get an 'n' figures "fraud" insurance when you purchase validated SSL certificates from commercial CA's and some standards require you to use them rather than LE and the likes. To my knowledge I do not know of any case on which that insurance has ever been successfully claimed so this entire premise should be just killed off completely. 'LE' and similar services should then be managed by a non-profit or a handful of those maybe for each region and just be done with it, the CA list is already too big and it's already near impossible to figure out who owns what besides the <10 big players. I honestly see no reason for SSL to work a browser have to have a list of 130-150 CA's on file (default Root+Intermediate CA listing on Windows).
- theandrewbailey 10y agoAnd by lots of other CAs, too. I've never seen a cert that has such a long chain (up to 10 intermediates), not to mention, multiple long chains. This probably would be trusted by most browsers (path 7), but one intermediate expired last month. https://www.ssllabs.com/ssltest/analyze.html?d=spi.dod.mil&s=140.31.150.110 https://www.ssllabs.com/ssltest/analyze.html?d=spi.dod.mil&s...
- Kadin 10y agoFor those who are interested (probably not necessary on a Mac as they may be preinstalled), the DOD CA certs can be freely downloaded from DISA: http://iase.disa.mil/pki-pke/Documents/unclass-installroot_v3-16-1a.zip http://iase.disa.mil/pki-pke/Documents/unclass-installroot_v... There are (impressively thorough, including recommendations on out-of-band fingerprint authentication) installation instructions included, and they provide PEM, PKCS7, and some weirdo Windows format.
- nneonneo 10y agoHowever, _that_ website is not served over HTTPS, which would seem to make it a prime target of MITM. Do you happen to have an HTTPS link to obtain these certs?
- deleted 10y ago[deleted]
- excalibur 10y agoOfficial source is here. The "MilitaryCAC" download link is publicly accessible, and uses SSL: https://militarycac.com/dodcerts.htm https://militarycac.com/dodcerts.htm Alternatively, the DoD certs served up securely by Symantec: https://knowledge.symantec.com/support/eca-support/index?page=content&id=SO5198 https://knowledge.symantec.com/support/eca-support/index?pag...
- jcurbo 10y agoMilitaryCAC is not an official source, it's about using CACs on personally-owned computers.
- jcurbo 10y agoI haven't found one, but I suspect the IASE page is only over HTTP for legacy reasons, as there are lots of things that download stuff automatically from DISA. I could be wrong though, and I agree that it should be served over HTTPS. The main DISA page is served over HTTPS: https://www.disa.mil https://www.disa.mil
- excalibur 10y agoI have the DoD root certs installed, my browser still isn't happy. It doesn't instill a lot of confidence in their encryption software when the website hawking it is still using SHA-1.
- fifteen_letters 10y agoCurrent software maintainer here. We have almost zero control over the webserver; it's run by a completely separate group of people. We can change some of the content, but next to nothing of the server config itself. (I realize that may sound strange to those of you who have never worked with any DoD organizations. Imagine going to one of the largest bureaucracies on the planet and saying, "We want you to change something.") So yeah, none of us are happy about the current situation. Trying to distribute security-oriented software via a website with a SHA-1 cert signed by a root cert that has to be installed separately... the irony is nearly poetic. Hoping to move to a completely different web host (still DoD, just different) before the end of the year. Most of us would be like, "we could do that in a day, plus DNS TTL expirations," but when they're not actually in combat, the DoD moves at... well, they move at the speed of government! :-)
- excalibur 10y agoLooks like they've since replaced it with a SHA256 cert. It was issued on the 22nd, so apparently they were already in the process of fixing it when this was posted to HN.