WoSign and StartCom has been included as root CA in official Android builds. 
(https://code.google.com/p/android/issues/detail?id=71363 
https://code.google.com/p/android/issues/detail?id=21632)

Apple has restrict/remove WoSign and StartCom from iOS 10.2.  "Google has 
determined that two CAs, WoSign and StartCom, have not maintained the high 
standards expected of CAs and will no longer be trusted by Google Chrome, in 
accordance with our Root Certificate Policy. " The announcement didn't say 
anything about Android. Is there any plan to restrict remove WoSign and 
StartCom from Android?
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to