4 ms·
I of course feel a little singled out here but as has been called out by Adam many (if not all) trusted roots have this same offering. It is allowed by all the
by rmhrisk 14y ago
I of course feel a little singled out here but as has been called out by Adam many (if not all) trusted roots have this same offering.
It is allowed by all the root programs.
The practices (both technological and procedural) we put around our program are some of the best in the industry, we take this responsibility very seriously.
More over we very rarely do it and instead work with customers to utilize our managed PKI offerings where we operate the infrastructure on behalf of the customer.
- marshray 14y agomany (if not all) trusted roots have this same offering Really? Care to name names? If this is so common, allowed, and totally above-board, why is the industry being so secretive about it? Why won't the CA industry disclose even the number of sub-CA (constrained critically, noncritically, or not at all) private keys in possession of 3rd parties (HSMs or no)?
- rmhrisk 14y agoJust look at the root program members in the Mozilla program, look at EFF data or the great notary.icsi.berkeley.edu/trust-tree/ As for disclosing all CAs have agreed to disclose -- no secret here at all. And clearly from this thread I am being very open :)
- marshray 14y agoThose projects show sub-CAs actually seen in public scans. They don't show all the sub-CA certs that could be used to compromise one's own security. We don't even have any idea what percentage of sub-CAs they show. For example, I doubt they show the TURKTRUST sub-CA that was used in an actual MitM of Google (and likely many others). This is not directed specifically at you @rmhrisk, but it's really disappointing how everyone involved in PKI seems to have a systematic habit of pretending like clearly identified potential risks and vulnerabilities are equivalent to impossible until (and sometimes even after) they're actually caught being used in an actual exploit.
- rmhrisk 14y agoMarsh, I understand your concern and I share it though I don't agree with the conclusion (re sticking head in the ground). With that said GlobalSign has committed to implementing CT and we hope all other CAs agree to do the same as Adam points out earlier in this thread its the way to bring the desired transperancy. That said it alone inst enough either, to start we also need TACK (and/or HSTS pinning), CAA, robust revocation checking and Name Constraints. And while conversations like this are uncomfortable (certainly for me being on the receiving end) I think they help too.
- marshray 14y agoSo are you proposing that 3rd party sub-CAs be brought under public CT? I could get on board with that.
- rmhrisk 14y agoI believe for CT to "work" all CAs on the public internet need to participate. I also believe that certificate transparency by itself is insufficient and the other items I mentioned are also needed.