4 ms·
They do and that's is specifically what this offering is about. However our policies have always been that those entities need to meet the same requirements (o
by rmhrisk 14y ago
They do and that's is specifically what this offering is about.
However our policies have always been that those entities need to meet the same requirements (operationally, etc) as we do which includes not participating MiTMs with any key material associated with that PKI.
Those customers who do have such CAs are also (normally) subject contractual restrictions to what namespaces they can issue against and they are always subject to audits where we confirm their usage is consistent with those policies.
In the very rare cases where that is not the case they are audited to meet the exact requirements we meet - we almost never do this.
It’s a difficult problem as a whole, there are legitimate use cases that help secure the web and enable commerce that are best served by having publicly trusted certificates our goal as an industry is to find ways to address those needs while reducing the risk.
To that end when I joined GlobalSign a year ago (from Microsoft) one of the first things I did was started here to advocate the industries use of name constraints as a means to reduce risk for all parties involved in these scenarios.
Ryan
- tptacek 14y agoThanks. I'm sorry, I knew MITM wasn't the only or most common reason enterprises wanted these certs, but wrote lazily. Are the nameConstraints extensions on these certs marked critical? I didn't know they could even be non-critical (one RFC says they can't) but 'agl says otherwise and would know.
- rmhrisk 14y agoThat's the position we start with when we engage with a customer but its dependent on the community in which they are going to communicate with. To be honest in most cases today (due to Safari) criticality is not enabled on most deployments.
- tptacek 14y agoArgh.
- lawnchair_larry 14y agoAs far as I'm concerned, that is in fact a MITM cert. Because you can technically MITM. When it comes to crypto and the level of trust that the entire world puts into this, this is the only definition of "MITM cert" that matters.
- tptacek 14y agoYou can only MITM Safari & Opera with that cert, FWIW.
- JoachimSchipper 14y agoThe only browsers you can MITM are Safari and Opera, yes. Stuff like https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-... would be worrisome enough without people creating certificates that, according to anyone's best reading of the standards at the time the software was written, should be globally accepted CA's.
- lawnchair_larry 14y agoYou seem to think that SSL is only for browsers.
- tptacek 14y agoI think that to a first approximation CA trust only matters for browsers, because non-browser applications have a whole panoply of other mechanisms that they should already be using to ensure the authenticity of SSL certificates. To put it differently: people running non-browser applications tend to have more control of their destiny. It's interesting that we bring this up, because it makes me now think that maybe the best way to jumpstart TACK is to implement it as a library that IOS programs can use.