logoalt Hacker News

agwatoday at 2:31 AM1 replyview on HN

It doesn't comply with one or more root store policies (which all incorporate the Baseline Requirements by reference, which incorporate various specs, such as RFC5280, by reference).

Mozilla root store policy: https://www.mozilla.org/en-US/about/governance/policies/secu...

Chrome root store policy: https://googlechrome.github.io/chromerootprogram/

Apple root store policy: https://www.apple.com/certificateauthority/ca_program.html

Baseline Requirements: https://github.com/cabforum/servercert/blob/main/docs/BR.md

There are countless examples of non-compliant certificates documented in the Bugzilla component I linked above. A recent example: a certificate which was backdated by more than 48 hours, in violation of section 7.1.2.7 of the Baseline Requirements: https://bugzilla.mozilla.org/show_bug.cgi?id=2016672


Replies

jacquesmtoday at 10:32 AM

Something is badly borked when the protections against an imaginary problem cause a real problem.

show 1 reply