4 ms·
Stay the heck away from these small-time CAs. In particular if they are based in North America or have any ties to the US Goverment.
by lizardactivist 4y ago
Stay the heck away from these small-time CAs. In particular if they are based in North America or have any ties to the US Goverment.
- Hackbraten 4y agoAccording to the article, TrustCor doesn’t even own a physical mailbox. I don’t want to imagine how and where they might be keeping their root CA private key material.
- ikiris 4y agoLast I checked, servers don't need a mailbox to operate, even for long periods of time.
- Hackbraten 4y agoThe idea of keeping a CA root certificate on a server sounds pretty reckless. I sincerely hope that no root CA has done that, ever!
- CoastalCoder 4y agoOut of curiosity, where do companies keep really important private keys? A thumbdrive in some safe, and a few printed-out copies of the key just in case the thumbdrive fails?
- Hackbraten 4y agoThese resources explain it quite well, I think: - https://en.wikipedia.org/wiki/Key_ceremony https://en.wikipedia.org/wiki/Key_ceremony - https://cryptography.fandom.com/wiki/Root_Key_Ceremony https://cryptography.fandom.com/wiki/Root_Key_Ceremony You can even watch recordings of selected ceremonies on YouTube. Some of them are several hours long.
- jenny91 4y agoOn HSMs; purpose built hardware that tries to make it physically and programmatically impossible to extract the private key material. They're generated there during a key ceremony and never leave a HSM. They also generally require like 2 or 3 officers of the compnay with smart cards and personal PINs to actually do anything using the root CA (it only signs an intermediate cert like once in a blue moon or something). I'm pretty sure the CA/B Forum mandates all CA private keys to remain on HSMs (checked through audits).
- mananaysiempre 4y ago> I don’t want to imagine how and where they might be keeping their root CA private key material. The handling of key material is supposed to be checked as a part of the (required) yearly audits, which they have passed[1,2] (though the single auditor they’ve always used “does not audit any other publicly-trusted CAs”[3]). The links are in the Common CA Database (CCADB) [4], but it seems really hard to find a good publicly-accessible report page (I still haven’t found the older audits, for example). ETA: For TrustCor specifically, Kathleen Wilson (responsible for the Mozilla root store) has collected the audit reports on Bugzilla[5]. [1] https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=c8857fc5-b201-4c4c-8717-f455b10ff5bc https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?at... [2] https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=459d2155-e50c-4497-929c-ee8a57f77708 https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?at... [3] https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/khFRpuI_AwAJ https://groups.google.com/a/mozilla.org/g/dev-security-polic... [4] https://ccadb-public.secure.force.com/mozilla/IncludedCACertificateReport https://ccadb-public.secure.force.com/mozilla/IncludedCACert... [5] https://bugzilla.mozilla.org/show_bug.cgi?id=1801504 https://bugzilla.mozilla.org/show_bug.cgi?id=1801504