3 ms·
"We have been made aware of a potential incident and are shutting down all issuance" seems to lean towards the latter and not simply a technical issue :(
by mark_round 5mo ago
"We have been made aware of a potential incident and are shutting down all issuance" seems to lean towards the latter and not simply a technical issue :(
- tptacek 5mo agoJosh Aas is on the thread. It's a compliance issue, they expect to be issuing shortly.
- rvnx 5mo agoWhat if they get kicked out of trusted roots because non-compliant ?
- nicolas_17 5mo agoThat's why they take incidents like this seriously and stop issuance until it's fixed. They could get kicked out of trusted roots otherwise.
- nijave 5mo agoChange your config to ZeroSSL or another free ACME provider?
- wolrah 5mo agoYou don't get kicked out of trusted roots for non-compliance, you get kicked out for continuing to knowingly issue non-compliant certs, failing to revoke non-compliant certs in a timely fashion once discovered, etc. Pausing issuance immediately upon discovery of a compliance issue is the absolute correct response so as long as they do their followup appropriately there is absolutely zero risk of being distrusted.
- rvnx 5mo ago> You don't get kicked out of trusted roots for non-compliance Of course you do, it's the main reason CAs fix compliance issues so fast. Symantec, WoSign, Entrust, etc repeatedly had non-compliance issues and that led to them being removed (even if fixed) Here was not a big issue: they forgot a flag to narrow the delegation of trust (but nobody knew that a few hours ago) Still it can be very problematic, there is a quite similar situation here https://bugzilla.mozilla.org/show_bug.cgi?id=1883843 https://bugzilla.mozilla.org/show_bug.cgi?id=1883843 A basic non-compliance issue, just a web link missing, but huge consequences if they don’t fix it. Repeated non-compliance (like the Symantec) will eventually get you removed even if fixed. The core definition of losing “trust” in someone. Keep in mind that few hours ago, nobody knew what the violation was. Turns out it was an easy fix.
- tptacek 5mo agoYou didn't actually respond to what the preceding comment argued. They were just pointing out the distinction between Symantec and WoSign and ordinary compliance events.
- Dylan16807 5mo agoWhat makes you think that?