4 ms·
Do I also understand correctly that a certificate was issued recently based on proving ownership of a domain ten years ago? That also sounds like a serious iss
by felixhandte 6y ago
Do I also understand correctly that a certificate was issued recently based on proving ownership of a domain ten years ago?
That also sounds like a serious issue.
- tristor 6y agoTechnically, it appears that a validation link to prove domain ownership was sent 10 (or 11) years prior, but wasn't clicked until recently. The issue isn't that ownership was proven ten years ago, the issue is that the link to do so was still valid for such a long period of time rather than being expired.
- kevincox 6y agoWell yes. That was an obvious issue. However the point is that the email was received 10 years ago, so you are only proving that you had control of the domain at that time. Of course validation links should expire in a relatively short timeframe.
- tialaramex 6y agoRight. GlobalSign asserts in their incident report that: > All other orders in the GCC platform that are older than 1 year and have not been fully processed (940909 orders) have been moved into a cancelled state on 9/02/2021. So (in this platform at least, and I believe this is either their oldest or one of their oldest legacy platforms) until this fix there were actually almost one million such certificates that could in principle be created based on information over a year old. They've attached a list of 112 other certificates that really were issued - and I think a reasonable person would judge should not have been issued, all have expired (and so there's no point in revoking them now). This at least shows they were thinking about the potential wider problem and not just focused on damage control for this one certificate, so that's something. The reference to "Ballot 169" is to the Ten Blessed Methods, Ballot 169 was a vote by the CA/Browser Forum to modify the Baseline Requirements to require these specific methods (today there aren't actually ten of them, but the general idea of spelling out how to validate control remains) rather than allowing CAs to each make up whatever methods of domain validation they thought would be good enough in their opinion. Ballot 169 actually got caught in a big bureaucratic mess but Mozilla forced the issue by making the Ten Blessed Methods part of its own rules anyway while the mess was sorted out so the CAs had to obey. Under the Ten Blessed Methods there's an explicit deadline, the random codes they're sending out by email are only good for thirty days. But I think we can judge from this that GlobalSign's prior method never expired codes at all, and you can imagine that when a deadline was introduced nobody wanted to retroactively extend that deadline to previous codes. At the moment that decision happens it seems superficially OK. Last year it was OK for Sue in accounting to take six weeks to finally click the link, next year the Ten Blessed Methods mean we'll have to show a "I'm sorry this request has expired, please order again" message but why jump ahead, we should let Sue's old order go through whenever she gets around to clicking it. It takes a particular type of person to ask "What if Sue takes six years instead of six weeks?" and those sorts of people don't tend to work for a CA. For example, the Chrome browser has code to actually enforce the requirements limiting leaf certificate lifetimes. In the modern era the browser code matches exactly what the rules say. Slightly before that the rules are rather woolly and so the browser approximates them, how long is "39 months" in terms a machine can understand? Chrome's programmers worked out a rationale for 1188 days as the answer. But at the outset there just weren't any rules. You could react to that by saying OK, if the certificate claims to have been issued in 1995 then I guess we believe them and accept any validity period whatsoever. 40 year leaf certificate? No problem. This opens an enormous security hole. So, Chrome's engineers just picked 10 years. And just like that, the hole closes, because sure enough it has been more than 10 years since the last date when such "No rules" certificates could be issued, and so there are no certificates issued recently enough to be unexpired which are allowed a ten year expiry.
- schoen 6y agoTialaramex, your PKI history analysis is a treasure of Hacker News!