6 ms·
I should probably add that the requirements that those customers have to meet go far beyond storage of the key material on a HSM (re: technical controls impleme
by rmhrisk 14y ago
I should probably add that the requirements that those customers have to meet go far beyond storage of the key material on a HSM (re: technical controls implemented in the device in which it's held).
Ryan
- tptacek 14y agoThere is a basic concern about "nuclear proliferation" of X.509 CA=YES certificates, since it is unlikely that any medium-sized collection of enterprise networks can among themselves safeguard the entire equivalently-sized set of corresponding certificates. Enterprise internal network security is surprisingly and creatively bad. That said, if we're (a) in a universe where critical:true nameConstraints are enforced on the last couple versions of Safari, Chrome, Firefox and IE, and (b) you're only issuing critical:true nameConstraints certificates, it probably isn't worth being alarmist here. In any case, thank you for commenting here. I had hoped to have a chance for once to join my fellow HN commenters in a rousing game of baying at the moon over the injustice of it all, but instead find myself amidst a carnival of X.509 learning. Hooray? TACK can't get here fast enough!
- rmhrisk 14y agoI totally understand the concern and I think the CA industry as a whole does as well. Moving forward Name Constraints will be adopted (finally) which is a good thing. Today it is supported by the majority of devices on the internet and given how fast browsers update now it wont be too long until the extension can be marked critical. On a semi-related note check out how many governments have their own roots : http://unmitigatedrisk.com/?p=181 http://unmitigatedrisk.com/?p=181
- harshreality 14y agoWhat certificate lifetimes are on these CA certificates you're issuing without critical name constraints? Will you reissue them all (for free) once you decide to start marking new ones critical? Will you require all such entities get reissued certs? Can you contractually require that they destroy the old certificates? Then there's the matter of how problematic OCSP is; even if you revoke the old ones, it may not matter.
- rmhrisk 14y agoLifetime varies, but yes the goal is to re-issue them once criticality is viable -- customers are contractually obligated to support that migration also. Said migration would ave no cost from us on the customer, I can't speak to what the other CAs do.