Fair enough

Impact is this:

As a retail organization we are in a moratorium till 1/2/2019 this happens 
every year. So nothing is being done that may jeopardize selling of widgets!

A process was put in place for 2wayssl where we'd name the cert based on what 
it does (so 2wayssl_to_from.domain.com) which we would then use for our own and 
partner vendor applications.

the scope of the main project if ~120 certs across a similar number of vendors. 
One of the home grown applications also hardcode the name of the certificate 
into the application and will require not only certificate update in 
coordination with the vendors but code changes on 120 certs in 12 days.

The project owners claim that timeline is impossible, and deploying 30 day 
validity certs is a similar level of effort without the code changes, and even 
that may not be possible. 

This particular application is how we link with our partners for activation and 
generates ~2b per year in revenue. 

To be perfectly clear here. We are 100% on board with a depreciation of the 
underscore (once we learned there was and issue with them from our CA we 
started restricting their issuance) The issue is I tell application owners this 
needs to be done, they want to know why they aren't even getting the 90 days 
they'd get if these were depreciated less aggressively (same they had for SHA1) 
for something that has not been a problem till now, and does not pose a 
security vulnerability. 

As it sits from CA alerting us to the final outcome we got 44 days, 31 of which 
are over a holiday moratorium. 


So for full scope: 260 certs out of compliance in my enterprise (out of ~17,000 
current valid certs) 

Of those 120 are problematic to replace in time, but could easily be done by 
the end of Q1 

If I could get browser blessing to give us at least Q1 to finish this it would 
make the entire world a much better place for me :) 



 

On Friday, December 7, 2018 at 8:39:15 AM UTC-7, Jeremy Rowley wrote:
> Personally, i think you should continue the discussion here. Although you can 
> bring it up to whichever ca you use, the reality is that without the browsers 
> knowing why the certs cant be replaced and the number, theres no way to gauge 
> their reaction to a non compliance. The penalties may include root removal 
> (see symantec) so I doubt many cas would be willing to risk a qualification 
> without clear guidance from the browsers on the risk associated with the non 
> compliance.
> ________________________________
> From: dev-security-policy <[email protected]> on 
> behalf of pilgrim2223--- via dev-security-policy 
> <[email protected]>
> Sent: Friday, December 7, 2018 8:26:42 AM
> To: [email protected]
> Subject: Re: CA Communication: Underscores in dNSNames
> 
> Thank you very much for your response!
> 
> So at the end of the day I will not get any relief from the browsers, and 
> will need to get an exception from my CA?
> 
> When I asked the CA they told me to take it here. Feels like the CA is where 
> I'm going to have to focus!
> 
> Thanks again for your time!
> 
> _______________________________________________
> dev-security-policy mailing list
> [email protected]
> https://clicktime.symantec.com/a/1/nN3YNjTD37Z9bk8efCYXsWHpyw8ViK61Q8Dz1AzUtno=?d=cQ4KQMo02NQvJ7GQxkZHfn9YbOkOTiGLFwgAhzovU-ksifF97AFzeTEl3fKU1c4flMJM5MQa4SYfNOuCB5-Y29jyEtL2_9KBxlVmHB_-8X_yPT3Gd1KBASJgcwXjKaIjjc7h8rFYLmo4FmmjdQDJfQcxl_q00tAfBZTdTqkwLD4b__i1PLIwekimsAKnCEc7M1LQPr1uSNB-FjHnEcF14WbG_18ILSXzHM34tK_cdKnINlfFOEvMSGXK7LVBeRjiRGTuodckiUppT5eIbtRZNKo6R8hoXcUzy-yTZ21EbW651pPGEqEwRb1Qpu9J0tLL6DExVNq6euprfMtWQTwjpQGvzkg5KO26pXSnafFpMBxblo_G0EcAZEMPzGWZrQxxtD8_wSHTTO7-9MbzrQGF8qAWuuFbGW-M220s2HRhgU8qz_qZtto%3D&u=https%3A%2F%2Flists.mozilla.org%2Flistinfo%2Fdev-security-policy

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to