15 ms·
Add Amazon root certificates
- aaronpk 11y agoDoes it bother anyone else that the links Amazon provided to their certificates and CRLs are not https?
- Titanous 11y agoThe fingerprints are included in the bugzilla ticket and the CRLs are signed with the certificates, so TLS doesn't technically add anything as long as you confirm the fingerprints (though it doesn't hurt anything either).
- aaronpk 11y agoYeah, it just seems odd
- qrmn 11y agoI don't think CRLs usually are, under current infrastructure anyway. How can you verify the certificate of the server when it's signed by the certificate you want to fetch; or check that it hasn't been revoked when what you're connecting to is its own CRL/OCSP? What about the risk of infinite loops? Cross-signatures, or multi-signatures, perhaps; or going opportunistic and simply not minding on that occasion? Nope, for now they just use HTTP, and pin what they need to, to the fingerprint. They should, however, specify an SHA-256 fingerprint. SHA-1 doesn't really cut it anymore. But that's what Mozilla currently require, so that's what Amazon provided. https://wiki.mozilla.org/CA:Information_checklist https://wiki.mozilla.org/CA:Information_checklist
- MichaelGG 11y agoNo it's not. In order to establish a TLS connection, you'd have to do a revocation check. Can't perform that if you need a TLS connection to get the CRL. As far as the certificate, I'm guessing there are many, many checks as to the authenticity of the key before it ships. Plus, they'd have to use a cert from another CA, since theirs are not trusted yet. That's not elegant in a process that is used to start CAs.
- mahouse 11y agoIt's normal, since their CA certificates aren't added to Firefox yet :-)
- dlgeek 11y agoThe CRL part is according to the standard RFC 5280, Section 8 (Security Considerations): "CAs SHOULD NOT include URIs that specify https, ldaps, or similar schemes in extensions." (https://tools.ietf.org/html/rfc5280 https://tools.ietf.org/html/rfc5280, page 103)
- DanWaterworth 11y agoPeople having obscure knowledge never ceases to impress me. (It's page 104 though ;P )
- lucb1e 11y agoI knew that as well because I was equally surprised that the revocation lists are over HTTP and looked this up, only I did this a few years ago. Not very obscure in my opinion.
- zwily 11y agoAn obvious move for Amazon. They'll be able to make SSL certificate management pretty painless for people using ELB.
- eli 11y agoI wonder if they have plans for CloudFront too. That'd be a killer feature to be able to use HTTPS on cloudfront on a custom domain without it costing a fortune.
- x5n1 11y ago> costing a fortune. The problem is not the SSL certificate, the problem is the IP address. That will no longer be a problem as soon as IPv6 takes hold in a few years, I give it about 3. They currently have to deploy the SSL certificate to over 30 different IPs hence it costing the immense amount. The certificate can be had for $10.
- toomuchtodo 11y agoWhy would anyone use non-SNI SSL/TLS anymore? Are there really that many Windows XP clients out there?
- eropple 11y agoOne of my clients still sees a surprising amount of Android 2.x traffic. Other than that, yeah, I can't see a reason.
- mike-cardwell 11y agoExactly. I default to SNI being acceptable now, unless somebody has convincing evidence that for their particular use case they can't use it.
- eli 11y agoI dunno where the line it, but Windows XP is in the ballpark of 2% of our traffic, depending on the site and how you measure it. The bummer is that HTTPS breaks kinda badly if you use an SNI cert and the OS/browser doesn't support it.
- x5n1 11y agoThe community needs to figure out a way to demonopolize this business and make it ubiquitous without destroying its credibility.
- justinsb 11y agoI think the EFF has (and is making great progress towards launching it): https://www.eff.org/deeplinks/2014/11/certificate-authority-encrypt-entire-web https://www.eff.org/deeplinks/2014/11/certificate-authority-...
- ceejayoz 11y agoThey're trying: https://letsencrypt.org/ https://letsencrypt.org/
- rsync 11y ago"The community needs to figure out a way to demonopolize this business and make it ubiquitous without destroying its credibility." Did you mean " ... while restoring its credibility, which has long since been destroyed" ?
- madez 11y agoA typo in the introduction: "We do not require customers that customers have a domain registration (...)" There is a "customers" too much.
- amyjess 11y agoAnd I can see exactly how they got to that mistake... The writer was waffling between "We do not require customers to have a domain registration" and "We do not require that customers have a domain registration", and they forgot to remove the entirety of the old wording when replacing it with the new. I've made this mistake myself several times, and it jumps out at me whenever I see it.
- provost 11y agoVery fitting. 'Customer Obsession' is Amazon's first leadership principle [1]. [1] http://www.amazon.jobs/principles http://www.amazon.jobs/principles
- jshb 11y agoWhat's the problem? It seems totally fine to me, but I'm no English native.
- dtparr 11y agoAs he says, there's an extra 'customers'. It should have been either "We do not require that customers have a domain registration (...)" or "We do not require customers to have a domain registration (...)"
- teoruiz 11y agoHow long will it take for the CA to be distributed to a large enough browser base? I mean, it could be years. Is there any other, speedier process? (cross-signing, for instance).
- kbrosnan 11y ago8 to 12+ months for it to be in a release version of Firefox. https://wiki.mozilla.org/CA:How_to_apply#Timeline https://wiki.mozilla.org/CA:How_to_apply#Timeline and https://wiki.mozilla.org/CA https://wiki.mozilla.org/CA document the process in great detail.
- alexchamberlain 11y agoDoes that go for new root certificates as well?
- michaelmior 11y agoI wonder how long it will take before it becomes practical to rely on Amazon-issued certs.
- elcct 11y agoSince Amazon is an American company, would you trust their certificates? I mean are they going to give private keys to NSA or whoever is now spying in the US?
- ceejayoz 11y agoThere isn't a single CA in existence that wouldn't be subject to nation-state pressure and/or infiltration. If NSA/GCHQ/FSB/etc. want to MITM you, they can probably MITM you.
- nucleardog 11y agoI've always enjoyed James Mickens' perspective on this: "In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@ virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https:// https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them. In summary, https:// https:// and two dollars will get you a bus ticket to nowhere. Also, SANTA CLAUS ISN’T REAL. When it rains, it pours." (From "This World Of Ours" - http://research.microsoft.com/en-us/people/mickens/thisworldofours.pdf http://research.microsoft.com/en-us/people/mickens/thisworld...)
- vacri 11y agoWhile entertaining, this is a bit like saying that there are only two kinds of vendors: beach stalls that sell you icecream; and giant multinational conglomerates that have huge department stores. In reality, there's plenty of folks in-between.
- higherpurpose 11y agoWhy would I trust a company like Amazon with a root certificate when it doesn't even use HTTPS across its website?
- dangrossman 11y agoNeither do Verisign, Entrust, TrendMicro, IdenTrust, StartCom which are root certificate authorities your browser trusts right now. All of their sites are accessible over HTTP. It doesn't really say anything about whether you should trust their CA businesses.
- umanwizard 11y agoThe GP wasn't pointing out that Amazon is "accessible over HTTP". He was making the much stronger point that Amazon doesn't even offer HTTPS on most of its site.
- bkeroack 11y agoThe latency increase for HTTPS actually causes a measurable conversion difference in the e-commerce space. It sucks but it's true. edit: Downvoters--have you ever done measurements? Why do you think Amazon redirects HTTPS to HTTP for product pages? It actually matters and at their scale it's real money.
- umanwizard 11y agoWhy would a redirect from https to http and then an http page load be faster than just returning the page over https? You're taking the SSL handshake latency hit either way.
- tomjen3 11y agoYou arguably shouldn't. We have way too many providers of certs as it is (including the Hong Kong post office, because reasons). The answer isn't to attack Amazon, but to move to a model where basic certs (including wild card certs) are free or you don't get your root certificate in, only 3 companies get their cert in and none of the may be based anywhere but Germany or other countries that respect privacy. But that is just the opinion of this random, angry, nerd.
- deleted 11y ago[deleted]
- dandroid1 11y agoYou shouldn't trust Amazon, Google, Facebook, MSFT, Twitter, or any other mega corp, really. Just don't use the internet at all!
- deleted 11y ago[deleted]
- ne0n 11y agoThat article is quite old (from Jan 2012). Amazon's independent publishing platform has extensive checks for plagiarism and content that is freely available on the internet. I know this system was there at least 6 months after that article. Source: I used to work at Amazon in Independent Publishing.
- reipahb 11y agoThis being Amazon AWS gives me hope that this will be a CA with an API that allows automatic certificate issuance for domains you control. I find the process of issuing and reissuing certificates for all sorts of services to be an increasing amount of work as more and more services move to https. (The letsencrypt.org CA is build around automated certificate issuance through an API, but some competition wouldn't be a bad thing.)
- agwa 11y agoCheck out SSLMate, which has been automating certificate issuance since early last year: https://sslmate.com https://sslmate.com We have both an API and a highly scriptable open source command line client.
- techsupporter 11y agoSeems very clever, but I have to ask: > DV certificates are $15.95/year per domain, Not a bad price, very much one I'd be willing to pay in order to get certificates via a CLI. > or $149.95/year for unlimited sub-domains. Ouch, 10x for a wild card? Why do issuers do this? It really puts a crimp on the whole "hobbyist doing hobbyist things" since that's $150/year just to not have cert errors on a single domain. (FWIW, I'm deliberately excluding StartSSL for a variety of reasons.)
- digi_owl 11y agoCould be it also discourages script kiddies from pulling antics.
- madaxe_again 11y agoNot sure why you've been downvoted - this is pretty much the reason for elevated pricing of wildcard certs. They are more open to abuse (have seen them used for phishing sites), so the issuer carries a higher risk of having to do additional management around the cert (i.e. revocations), so therefore charge more.
- 11y ago
- rmoriz 11y agoplease support S/MIME!