Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Tue, 23 Dec 2008 12:39:03 +0200
Local: Tues, Dec 23 2008 5:39 am
Subject: Re: Unbelievable!
On 12/23/2008 07:09 AM, Frank Hecker:
> There are two general reasons for pulling a root, to address a clear and As long as this site keeps operating, our customers are still being let > present danger to Mozilla users, and to punish a CA and deter others. My > concern right now is with the former. I see at least three issues in > relation to that: > 1. Issuance of further non-validated certs by this reseller. Comodo to believe that they have to renew their certificate with them. This is only a reminder about how it started at all. CAs and their customers are still taking damage from the previously sent messages. > 2. Potential problems with certs already sold through this reseller. relying parties. How to do that is up to you and Comodo I guess. Comodo not only shouldn't just investigate and take action, Comodo needs > Pulling a Comodo root will knock out Firefox, etc., access to thousands I'm not advocating removing their root, however we must assess the risk > of SSL sites, maybe tens of thousands. which is potentially caused to the relying parties. There may be thousands of sites which received certificates without validating them. > Given the disruption that would Disabling the trust bits of "AddTrust External CA Root" could be a > cause, the final decision on this IMO should be made in conjunction with > the Firefox security folks. temporary measure to prevent damage to relying parties until Mozilla receives full report and disclosure from Comodo about its resellers and conclusion of their investigation. Additionally instead of just yanking a root as a deterrent and -- Signer: Eddy Nigg, StartCom Ltd. You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||