5 ms·
> There's millions of internet-connected set top boxes, tvs, and dvd/bluray players deployed around the world that run with a limited set of supported CAs. Wha
by Pyxl101 9y ago
> There's millions of internet-connected set top boxes, tvs, and dvd/bluray players deployed around the world that run with a limited set of supported CAs.
What exactly is the issue? If an embedded device trusts Symantec CA, then connections from the device to its central servers will continue working without interruption.
In this example, the device trusts the Symantec CA, and the server presents a certificate signed by the Symantec CA. Everything's hunky-dory. What's the problem?
- will_hughes 9y agoClients have no way to indicate what CAs they trust, so my infrastructure has to just present a certificate and say "Here I am" So now if Google go ahead and distrust Symantec CAs, I need to duplicate that infrstructure (or at least the configuration at load balancers, etc) - this leads to all sorts of complexity.
- Pyxl101 9y agoThat certificate can be signed by whatever CAs you wish to use, including Symantec and others.
- peeters 9y agoYou have api.mysite.com which serves both an embedded device as well as your site. To allow the site to be viewed in Chrome, you need a new cert for your API, and so you now have to either update your site to point to a different endpoint, or update your devices to accept the new cert. Sure it might be easier to do the former for some companies, but either way there's certainly a cost.
- Pyxl101 9y agoSure. If api.mysite.com supports both web browsers and embedded devices, then you can issue a certificate for it your publicly-trusted CA of choice, and then can cross-sign that certificate with the Symantec CA.