3 ms·
My niaive understanding is that all certs contain (at least) the id/thumb of their issuing cert - If I am not mistaken, how is TLS broken by sending only the le
by Jenk 3y ago
My niaive understanding is that all certs contain (at least) the id/thumb of their issuing cert - If I am not mistaken, how is TLS broken by sending only the leaf and/or intermediary if the client is able to correctly identify the issuer as known/trusted via this thumb print?
- politelemon 3y agoIf I'm understanding correctly, the post isn't calling TLS broken, it's calling out the bad behavior of browsers. By employing mitigations/workarounds, they encourage misconfigured servers, and that in turn produces unexpected or inconsistent behaviors when interacting with those servers through different client types. eg you might see different behavior in FF vs Chrome, or Chrome vs curl/python, etc.
- Jenk 3y agoApologies, I didn't mean breaking TLS itself but breaking the trust that said protocol is providing. Thanks for explaining.
- tialaramex 3y agoYou can do this, and historically some browsers did, it's called AIA chasing (which is why AIA is mentioned briefly in the blog post) The problem with AIA chasing is that it's a privacy violation. Not a huge one but enough to be completely unacceptable for say Mozilla. In fetching the needed intermediates we reveal which intermediates we needed, if you're Let's Encrypt you operate only a few intermediates and you issue a truly astounding number of certificates from each so that's barely information, but if you're a small CA and you have say a dozen intermediates you absolutely could arrange for say pro-Party A sites to all use intermediate #6 while also pro-Party B sites used intermediate #8 and then use the resulting data from AIA chasing to measure who is going to "Party A" sites and direct political advertising at those people...