4 ms·
WoSign's response[1] might also be of interest in this context. They seem to take, at least partially, ownership of the issues. Am I also correct in that this
by markild 10y ago
WoSign's response[1] might also be of interest in this context.
They seem to take, at least partially, ownership of the issues. Am I also correct in that this only affects intermediate certificates? I see they say that they will have a workaround in place in about a months time.
[1]: https://www.wosign.com/English/News/announcement_about_Mozilla_Action_20161024.htm https://www.wosign.com/English/News/announcement_about_Mozil...
- jlgaddis 10y ago> Am I also correct in that this only affects intermediate certificates? No. As the article states, it will affect any certificates that chain up to the specified root certificates (including and intermediate and end-entity certificates). > I see they say that they will have a workaround in place ... From previous statements, I believe WoSign's plan is to resell another CA's certificates during the period that they don't have a root of their own in the trust store.
- pilif 10y ago> From previous statements, I believe WoSign's plan is to resell another CA's certificates during the period that they don't have a root of their own in the trust store. or find/buy another currently trusted CA that cross-signs their new root. I'm sure they can find somebody. edit: yes. that's what they are going to do according to https://www.wosign.com/English/News/announcement_about_Mozilla_Action_20161024.htm https://www.wosign.com/English/News/announcement_about_Mozil...: > There will be new SSL certificates issued by a new WoSign intermediate CA which is signed by the one of global trusted root CA, it supports all the browsers (including Firefox). This will be done within one months. I wonder who's going to be stupid/reckless enough to sign that intermediate.
- tankenmate 10y agoIndeed, any company that signs any of their intermediates would want to have an ironclad indemnification, penalty clauses and a fully paid up escrow (hosted in a neutral country like Switzerland, Ireland or the like) in any contract. But I suspect that another Chinese company or Chinese owned company will be selected to be the signor.
- pfg 10y agoIt remains to be seen whether they will actually hold the private key for that intermediate certificate and issue end-entity certificates from it, or if this is just some sort of reselling deal where a different, trusted CA holds the key, performs domain validation, etc (which is a fairly common practice). I have my doubts about whether Mozilla will accept them continuing to operate an actual CA with a new cross-signed certificate prior to them completing the inclusion process. CAs need to disclose these intermediate certificates, and I expect it would end up being revoked, with possible sanctions for whoever cross-signs them.
- bandrami 10y agoI wonder who's going to be stupid/reckless enough to sign that intermediate. You have a much higher opinion of the probity (and competence) of CAs than is probably warranted.
- TravelTechGuy 10y agoI've noticed 2 things in their response: 1. They take no direct responsibility, nor try to explain, or excuse the deception claims. To WoSign, the whole thing is "an incident", not a premeditated deception. 2. They still do not acknowledge their ownership of StartCom, or explain why that was kept in the dark. In fact they keep talking about "4 WoSign roots" despite the 6 roots mentioned by Mozilla.