3 ms·
Time and money. Plus right now even if you bought the infra, the staff, paid for and passed the audits, and then waiting while Apple, Mozilla, Google and Oracle
by nickf 2y ago
Time and money. Plus right now even if you bought the infra, the staff, paid for and passed the audits, and then waiting while Apple, Mozilla, Google and Oracle (at least) included your roots...Microsoft aren't taking more right now. So you have to wait for some unknown time in the future when/if they start doing that again.
You could purchase a root off an existing CA, subject to the trust stores approving it, and the boatload of cash you'd need to buy it (plus still having the staff and infra to operate it).
- skissane 2y ago> Microsoft aren't taking more right now. So you have to wait for some unknown time in the future when/if they start doing that again. Interesting, I hadn’t heard that, is there anywhere I can read more about it? > You could purchase a root off an existing CA, As well as a sub-CA, I remember in theory you can have two independent CAs with cross-signing… but do browsers actually support that?
- nickf 2y agoNothing public to point to, sorry. Sub-CAs: Not really. Operational risk to the parent CA is huge, you'd be hard pressed to get any current public CA to sign an issuing CA to be operated externally. Cross-signing still works (though it is the stuff of nightmares in many cases) but again you have to have money and a CA willing to do it!
- twisteriffic 2y agoEntrust is/was doing it with ssl.com after they were detrusted.
- nickf 2y agoNo, SSLCorp are hosting and managing a CA with Entrust branding. Same as Sectigo are doing. Entrust aren't doing issuance, verification - they're straight reselling from white-labeled issuing CAs.
- zinekeller 2y ago"Nothing public to point out to" is probably accurate but it is noted publicly here: https://learn.microsoft.com/en-us/security/trusted-root/new-ca-application https://learn.microsoft.com/en-us/security/trusted-root/new-...