On 09/06/17 11:16, Jakob Bohm via dev-security-policy wrote:
<snip>
What in the policy says they become in-scope from a certificate chain
that isn't "anchored" at a Mozilla trusted root?
And would someone please post those alleged certificate chains
*explicitly* here, not just say they saw it "somehow".
Hi Jakob. Let me run through one of them as an example:
https://crt.sh/?id=12977063 is a self-signed root certificate that is
also an NSS built-in trust anchor.
https://crt.sh/?id=149444544 is a self-signed root certificate that is
_not_ an NSS built-in trust anchor.
These two certs share the same Name and Key. Therefore, the signature
on the first can be verified by the public key in the second; and vice
versa. And clearly the Subject Name in each one matches the Issuer Name
in the other. This means that the first chains to the second, and also
that the second chains to the first.
The policy says:
"All certificates that are capable of being used to issue new
certificates, and which directly or transitively chain to a certificate
included in Mozilla's CA Certificate Program, MUST be operated in
accordance with this policy and MUST either be technically constrained
or be publicly disclosed and audited."
--
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy