On Sat, Dec 8, 2018 at 5:01 AM Richard Moore via dev-security-policy <[email protected]> wrote: > > > the scope of the main project if ~120 certs across a similar number of > > vendors. One of the home grown applications also hardcode the name of the > > certificate into the application and will require not only certificate > > update in coordination with the vendors but code changes on 120 certs in 12 > > days. > > It seems likely to me that these applications won't actually support OCSP and > updating any CRLs in use may well be a manual process too. So, if the > certificates were revoked, would your applications actually notice at all? > It's quite different from them expiring which is coded into the certificate > itself.
Even if these apps support revocation checking, their root stores might contain one or more ancient roots that are no longer needed by any WebPKI certificate, and could therefore be removed from BR scope and continue issuing underscore-containing certificates. When SHA1 was deprecated, Sectigo (née Comodo) requested root stores remove one of their roots [1], taking it out of scope for the BRs, and continued issuing "legacy" SHA1 certificates off of that root. Sectigo has also published a list of certificates containing underscores they will be revoking [2]; conspicuously absent from that list are four of these legacy SHA1 certificates [3]. Perhaps pilgrim2222's company (Verizon?) could convince a CA to do something similar here? Best, Alex [1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1208461 [2]: https://misissued.com/batch/41/ [3]: https://crt.sh/?id=701056092, https://crt.sh/?id=700688392, https://crt.sh/?id=701055930, https://crt.sh/?id=700688392 _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

