On 09/06/17 11:16, Jakob Bohm via dev-security-policy wrote:
<snip>
What in the policy says they become in-scope from a certificate chain
that isn't "anchored" at a Mozilla trusted root?

And would someone please post those alleged certificate chains *explicitly* here, not just say they saw it "somehow".

Hi Jakob.  Let me run through one of them as an example:

https://crt.sh/?id=12977063 is a self-signed root certificate that is also an NSS built-in trust anchor.

https://crt.sh/?id=149444544 is a self-signed root certificate that is _not_ an NSS built-in trust anchor.

These two certs share the same Name and Key. Therefore, the signature on the first can be verified by the public key in the second; and vice versa. And clearly the Subject Name in each one matches the Issuer Name in the other. This means that the first chains to the second, and also that the second chains to the first.

The policy says:
"All certificates that are capable of being used to issue new certificates, and which directly or transitively chain to a certificate included in Mozilla's CA Certificate Program, MUST be operated in accordance with this policy and MUST either be technically constrained or be publicly disclosed and audited."

--
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to