3 ms·
I totally understand the concern and I think the CA industry as a whole does as well. Moving forward Name Constraints will be adopted (finally) which is a good
by rmhrisk 14y ago
I totally understand the concern and I think the CA industry as a whole does as well.
Moving forward Name Constraints will be adopted (finally) which is a good thing. Today it is supported by the majority of devices on the internet and given how fast browsers update now it wont be too long until the extension can be marked critical.
On a semi-related note check out how many governments have their own roots : http://unmitigatedrisk.com/?p=181 http://unmitigatedrisk.com/?p=181
- harshreality 14y agoWhat certificate lifetimes are on these CA certificates you're issuing without critical name constraints? Will you reissue them all (for free) once you decide to start marking new ones critical? Will you require all such entities get reissued certs? Can you contractually require that they destroy the old certificates? Then there's the matter of how problematic OCSP is; even if you revoke the old ones, it may not matter.
- rmhrisk 14y agoLifetime varies, but yes the goal is to re-issue them once criticality is viable -- customers are contractually obligated to support that migration also. Said migration would ave no cost from us on the customer, I can't speak to what the other CAs do.