For these self-signed roots which have a certificate subject and key which match to a different certificate which is in a trusted path (like an intermediate to a trusted root), the concern is that the mere existence of the certificate speaks to a signature produced by a private key which DOES have the privileged status of extending the trust of the Web PKI.
The question then is whether that signature was properly accounted for, audited, etc. Additionally, if said root is in active use, are the issuances descending from _that_ self-signed root being audited? If not, that's a problem, because those certificates could just be served up with the same-subject, same-key trusted intermediate and chain to publicly trusted roots, all without having been actually issued from the trusted intermediate. _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

