4 ms·
Symantec is investigating: https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/fyJ3EK2YOP8 https://groups.google.com/forum/#!topic/mozilla.dev.s
by tetrep 10y ago
Symantec is investigating: https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/fyJ3EK2YOP8 https://groups.google.com/forum/#!topic/mozilla.dev.security...
I wonder what excuses we'll here this time, and if we'll lose a CA in the process.
- poizan42 10y ago> The listed Symantec certificates were issued by one of our WebTrust audited partners. We have reduced this partner's privileges to restrict further issuance while we review this matter. We revoked all reported certificates which were still valid that had not previously been revoked within the 24 hour CA/B Forum guideline - these certificates each had "O=test". Our investigation is continuing. So Symantec are letting third parties issue certificates using their root? Seems like a pretty bad idea when it's their own reputation that is on the line here. And also don't we have a system in place for that by using intermediary CAs that wouldn't require the certificates to be issued directly by Symantec?
- paulddraper 10y agoYes, I don't get that. What justification is there for another party signing with your root?
- tialaramex 10y agoFirst up I will nitpick. The certificates were issued from an Intermediate, "Symantec Class 3 Secure Server CA - G4" not from a root. Hopefully Symantec keeps all the actual roots safely physically off-line in smart cards or similar devices locked in a vault. Now, not to excuse them of anything (I shall be jumping up and down in m.d.s.policy once they write up something more substantive) I shall try to explain what they're on about Older public CAs (and Symantec is in effect the oldest, having inherited Thawte and Versign roots) have this complicated structure with resellers and affiliates under different contracts and with varying responsibilities. Particularly for the facts about organisations, like their official address, the registered name and so on, a local business can understand things better than some remote North American corporation. So it can make sense rather than trying to build out subsidiaries in every country to instead find a partner to do that stuff. Likewise it used to be common to out-source domain validation to third parties who were already in the domain naming game, such as registrars or hosting companies. Now, Symantec _should_ be keeping a firm rein on these things and exercising vigilance to ensure it knows what these partners / affiliates are doing in its name. But it's much harder to do that well than to have a much simpler setup where you can see all the moving parts for yourself and reason about the whole system.