Fair enough Impact is this:
As a retail organization we are in a moratorium till 1/2/2019 this happens every year. So nothing is being done that may jeopardize selling of widgets! A process was put in place for 2wayssl where we'd name the cert based on what it does (so 2wayssl_to_from.domain.com) which we would then use for our own and partner vendor applications. the scope of the main project if ~120 certs across a similar number of vendors. One of the home grown applications also hardcode the name of the certificate into the application and will require not only certificate update in coordination with the vendors but code changes on 120 certs in 12 days. The project owners claim that timeline is impossible, and deploying 30 day validity certs is a similar level of effort without the code changes, and even that may not be possible. This particular application is how we link with our partners for activation and generates ~2b per year in revenue. To be perfectly clear here. We are 100% on board with a depreciation of the underscore (once we learned there was and issue with them from our CA we started restricting their issuance) The issue is I tell application owners this needs to be done, they want to know why they aren't even getting the 90 days they'd get if these were depreciated less aggressively (same they had for SHA1) for something that has not been a problem till now, and does not pose a security vulnerability. As it sits from CA alerting us to the final outcome we got 44 days, 31 of which are over a holiday moratorium. So for full scope: 260 certs out of compliance in my enterprise (out of ~17,000 current valid certs) Of those 120 are problematic to replace in time, but could easily be done by the end of Q1 If I could get browser blessing to give us at least Q1 to finish this it would make the entire world a much better place for me :) On Friday, December 7, 2018 at 8:39:15 AM UTC-7, Jeremy Rowley wrote: > Personally, i think you should continue the discussion here. Although you can > bring it up to whichever ca you use, the reality is that without the browsers > knowing why the certs cant be replaced and the number, theres no way to gauge > their reaction to a non compliance. The penalties may include root removal > (see symantec) so I doubt many cas would be willing to risk a qualification > without clear guidance from the browsers on the risk associated with the non > compliance. > ________________________________ > From: dev-security-policy <[email protected]> on > behalf of pilgrim2223--- via dev-security-policy > <[email protected]> > Sent: Friday, December 7, 2018 8:26:42 AM > To: [email protected] > Subject: Re: CA Communication: Underscores in dNSNames > > Thank you very much for your response! > > So at the end of the day I will not get any relief from the browsers, and > will need to get an exception from my CA? > > When I asked the CA they told me to take it here. Feels like the CA is where > I'm going to have to focus! > > Thanks again for your time! > > _______________________________________________ > dev-security-policy mailing list > [email protected] > https://clicktime.symantec.com/a/1/nN3YNjTD37Z9bk8efCYXsWHpyw8ViK61Q8Dz1AzUtno=?d=cQ4KQMo02NQvJ7GQxkZHfn9YbOkOTiGLFwgAhzovU-ksifF97AFzeTEl3fKU1c4flMJM5MQa4SYfNOuCB5-Y29jyEtL2_9KBxlVmHB_-8X_yPT3Gd1KBASJgcwXjKaIjjc7h8rFYLmo4FmmjdQDJfQcxl_q00tAfBZTdTqkwLD4b__i1PLIwekimsAKnCEc7M1LQPr1uSNB-FjHnEcF14WbG_18ILSXzHM34tK_cdKnINlfFOEvMSGXK7LVBeRjiRGTuodckiUppT5eIbtRZNKo6R8hoXcUzy-yTZ21EbW651pPGEqEwRb1Qpu9J0tLL6DExVNq6euprfMtWQTwjpQGvzkg5KO26pXSnafFpMBxblo_G0EcAZEMPzGWZrQxxtD8_wSHTTO7-9MbzrQGF8qAWuuFbGW-M220s2HRhgU8qz_qZtto%3D&u=https%3A%2F%2Flists.mozilla.org%2Flistinfo%2Fdev-security-policy _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

