4 ms·
I think you're right about CRLSets. IMO, Mozilla really wanted to solve the problem, whereas Chrome just wanted to have a solution that they could use for emerg
by ivanr 3y ago
I think you're right about CRLSets. IMO, Mozilla really wanted to solve the problem, whereas Chrome just wanted to have a solution that they could use for emergency revocation of certificates of high-profile sites (and intermediates/roots). Small-time sites won't be in CRLSets, although if you know the right people and make enough noise you may be added to their list. As for Apple, no one knows what's going on because they don't like to share :)
OCSP must-staple doesn't require code changes. It's a "flag" you set on a certificate. Maybe what you mean is that OCSP stapling is not enabled by default on many installations, and that's true. IIS got it right, and Caddy (obviously, the only platform that got everything right).
Again, we're in this place only because browsers don't care about revocation. If they pushed for it, things would fall into place very quickly. But they're going in the opposite direction.
Short-lived certificates are great, assuming you're fine with a 3.5 day (on average) window of opportunity for exploitation. There's a potentially major problem with clock skew, as many clients have inaccurate clocks. Personally, I recommend that certificates are obtained at least a week before they're deployed; a month would be better. Then rotated a month before they expire. That's how you minimise the problems due to clock skew.
- e12e 3y agoAs far as I can figure out, most ocsp staples are valid for 7 days, so short lived certificates would be equivalent, but simpler?
- ivanr 3y agoIndeed, you're right. Must-staple and short-lived certificates have the same problem with clock skew.
- agwa 3y agoApple shared the details of valid.apple.com in a WWDC talk: https://devstreaming-cdn.apple.com/videos/wwdc/2017/701jvytnoey2yc7222/701/701_hd_your_apps_and_evolving_network_security_standards.mp4?dl=1 https://devstreaming-cdn.apple.com/videos/wwdc/2017/701jvytn... Slides: https://devstreaming-cdn.apple.com/videos/wwdc/2017/701jvytnoey2yc7222/701/701_your_apps_and_evolving_network_security_standards.pdf https://devstreaming-cdn.apple.com/videos/wwdc/2017/701jvytn... You can also find the client-side code if you dig around under https://opensource.apple.com/source/Security/ https://opensource.apple.com/source/Security/ It aims to cover all certificates, similar to Mozilla's CRLite.