Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rmhrisk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Simple tool to help create SSL certificate requests
(csrhelp.peculiarventures.com)
2 points
by
rmhrisk
11y ago
|
1 comments
32.
▲
by
rmhrisk
13y ago
Cool, I would love to see the source.
33.
▲
by
rmhrisk
14y ago
I believe for CT to "work" all CAs on the public internet need to participate. I also believe that certificate transparency by itself is insufficient and the other items I mentioned are also needed.
34.
▲
by
rmhrisk
14y ago
Marsh, I understand your concern and I share it though I don't agree with the conclusion (re sticking head in the ground). With that said GlobalSign has committed to implementing CT and we hope all other CAs agree to do the same as Adam poi
35.
▲
by
rmhrisk
14y ago
They need to meet the same criteria we do, here are some starting points but its far from exaustive: http://www.mozilla.org/projects/security/certs/policy/ http://social.technet.microsoft.com/wiki/contents/articles/3... http://www.webt
36.
▲
by
rmhrisk
14y ago
Just look at the root program members in the Mozilla program, look at EFF data or the great notary.icsi.berkeley.edu/trust-tree/ As for disclosing all CAs have agreed to disclose -- no secret here at all. And clearly from this thread I am b
37.
▲
by
rmhrisk
14y ago
The root programs all allow for technical and procedural controls to meet the this criteria. There are technical controls beyond name constraints as well. Again GlobalSign's policies do not allow the use of certificates that chain to our ro
38.
▲
by
rmhrisk
14y ago
I of course feel a little singled out here but as has been called out by Adam many (if not all) trusted roots have this same offering. It is allowed by all the root programs. The practices (both technological and procedural) we put around o
39.
▲
by
rmhrisk
14y ago
Lifetime varies, but yes the goal is to re-issue them once criticality is viable -- customers are contractually obligated to support that migration also. Said migration would ave no cost from us on the customer, I can't speak to what the ot
40.
▲
by
rmhrisk
14y ago
It does not.
41.
▲
by
rmhrisk
14y ago
Code signing is another beast all together, in 5280 (and its predecessors). EKU is used to restrict what certificates are good for, this bug explains a behavior the majority of code signing delegation is dependent on - https://bugzilla.moz
42.
▲
by
rmhrisk
14y ago
For us we require CAs that are not technically constrained to be independently audited to WebTrust for CA requirements, Moving forward thanks to Mozillas new policy the same will be true for all CAs.
43.
▲
by
rmhrisk
14y ago
Doing so right now would mean that apple users could not visit google.com or microsoft.com both of which who operate sub-cas chained to public roots. Deploying non-critical name constraints to the existing community of subcas reduces the ri
44.
▲
by
rmhrisk
14y ago
not currently, their move off of OpenSSL to their own libraries makes this more complicated for them to do but I am hopeful they will soon. Here is a summary of where clients were a year ago, opera has support now so its slightly out of dat
45.
▲
by
rmhrisk
14y ago
Thanks Adam, yes these are not MITM certificates. They are used by large environments like Google and Microsoft to issue certificates for their assets and people. They are contractually and technically (new but now standard) prohibited from
46.
▲
by
rmhrisk
14y ago
I totally understand the concern and I think the CA industry as a whole does as well. Moving forward Name Constraints will be adopted (finally) which is a good thing. Today it is supported by the majority of devices on the internet and give
47.
▲
by
rmhrisk
14y ago
That's the position we start with when we engage with a customer but its dependent on the community in which they are going to communicate with. To be honest in most cases today (due to Safari) criticality is not enabled on most deployments
48.
▲
by
rmhrisk
14y ago
I agree with Adam, support is actually quite good in modern libraries and this is in no small thanks to the good folks at NIST who published the PKITS tests for chain engines - http://csrc.nist.gov/groups/ST/crypto_apps_infra/pki/pkitest..
49.
▲
by
rmhrisk
14y ago
I should probably add that the requirements that those customers have to meet go far beyond storage of the key material on a HSM (re: technical controls implemented in the device in which it's held). Ryan
50.
▲
by
rmhrisk
14y ago
They do and that's is specifically what this offering is about. However our policies have always been that those entities need to meet the same requirements (operationally, etc) as we do which includes not participating MiTMs with any key m
51.
▲
by
rmhrisk
14y ago
I think you are misunderstanding. First off so there is no ambiguity let me say clearly that GlobalSign's policies do not allow the use of certificates that chain to our roots to be used for MiTM purposes (or other malicious use cases for t
52.
▲
by
rmhrisk
14y ago
Its true this wasn't a scientific test and I tried to be clear it wasn't trying to be. That said I doubt anyone would argue that performance doesnt have an impact on their bottom line, more over the three changes I mentioned would have a re
53.
▲
How Facebook can avoid losing revenue when they switch to always-on SSL
(unmitigatedrisk.com)
14 points
by
rmhrisk
14y ago
|
5 comments