9 ms·
Naturally, this led me to research how does one even become a CA? * Developing and implementing a robust security infrastructure * Completing an applicatio
by gzer0 4y ago
Naturally, this led me to research how does one even become a CA?
* Developing and implementing a robust security infrastructure
* Completing an application process
* Undergoing an audit and validation process
* Obtaining accreditation from a recognized organization
* Maintaining compliance with accreditation requirements.
and then:
* On average, it can take several months to a year or more to complete the process of becoming a CA. This includes the time required for developing and implementing the necessary policies and procedures, completing the application process, undergoing the audit and validation process, and obtaining accreditation.
Wow, throwing away several months to a year of effort. It truly is something that takes time. I guess, a determined adversary will play the long con.
- kseifried 4y agoWitness bjca.cn: https://groups.google.com/a/ccadb.org/g/public/c/o9lbCbr92Ug https://groups.google.com/a/ccadb.org/g/public/c/o9lbCbr92Ug The summary of the public discussion is worrying: Summary of Discussion and Action Items Discussion Item #1: A concern was raised about BJCA’s Beijing One Pass software, which apparently facilitates client access to a digital portal or platform. It was noted that BJCA had attempted to address suspicions about the software in Comment #15, that the software was needed to support a USB token and to install another certificate chain, and not the two above-referenced roots. A follow-up question was whether a security report concerning the software would be made publicly available. BJCA Response to Discussion Item #1: “This report is a communication document between our company and the competent government department, and it is not suitable for disclosure or submission to Mozilla because it involves confidential information. And because the security incident does not involve the certificate chain of the root inclusion case submitted to Mozilla this time, we made a clarification in the Mozilla root inclusion case by disclosing the main points of the report.” ========================== Discussion Item #2: Two components were also mentioned: wmControl.exe and zfkeymonitor.exe. BJCA Response to Discussion Item #2: The “suspected spyware behavior indicated in the report was caused by one of the drivers, wmControl.exe. This program is a driver provided by the USB Token manufacturer, Its software behavior is different from spyware and does not have malicious behavior. It is intended to ensure the normal use of this type of [device] in the browser. In addition, the USB Token for digital certificate corresponding to the driver wmControl.exe is an old version device, and its driver has been deleted in the new version of the certificate environment software (version >= 3.6.8)”. Concerning zfkeymonitor.exe, BJCA responded that their software did not include the zfkeymonitor program. ========================== Discussion Item #3: Clarification was requested about root certificate installation by the One Pass software. BJCA Response to Discussion Item #3: BJCA reiterated that their software did not attempt to install the two roots, but stated, “in order to improve the user experience, the BJCA certificate environment software chooses to skip user confirmation during the installation process, which may cause doubts for users. At present, we have plans to adopt advanced options in the new version of the software, allowing users to choose whether to confirm the installation, and support users to choose to add certificates and updates to the current user's personal storage instead of the computer's trusted root or trusted third party storage. No doubt that there is an obvious contradiction between convenience and security, which could improve the software security but degrades the user experience and increase our operation costs.” According to BJCA, it maintains two separate systems: a global, public-trust system that meets international standards (WebTrust, CA/Browser Forum, etc.) and issues and manages SSL/TLS server certificates; and a national system that follows Chinese standards and issues and manages personal certificates, enterprise certificates and equipment certificates (e.g., Beijing One Pass software and certificate). BJCA acknowledges that both systems are under control of the same legal business entity, but for the latter, the software is not part of the global, public-trust system. BJCA says it “will also refer to the recommendations of experts, learn from the best practices of the public trust system, continue to innovate, practice corporate social responsibility, and strive to build a safe and reliable of cyberspace.” ========================== Conclusion We thank community members for their review and consideration during this period. Root Store Programs will make final inclusion decisions independently, on their own timelines, and based on each Root Store Member’s inclusion criteria. Further discussion may take place in the independently managed Root Store community forums (i.e., MDSP).