On Sat, Dec 8, 2018 at 5:01 AM Richard Moore via dev-security-policy
<[email protected]> wrote:
>
> > the scope of the main project if ~120 certs across a similar number of 
> > vendors. One of the home grown applications also hardcode the name of the 
> > certificate into the application and will require not only certificate 
> > update in coordination with the vendors but code changes on 120 certs in 12 
> > days.
>
> It seems likely to me that these applications won't actually support OCSP and 
> updating any CRLs in use may well be a manual process too. So, if the 
> certificates were revoked, would your applications actually notice at all? 
> It's quite different from them expiring which is coded into the certificate 
> itself.

Even if these apps support revocation checking, their root stores
might contain one or more ancient roots that are no longer needed by
any WebPKI certificate, and could therefore be removed from BR scope
and continue issuing underscore-containing certificates.

When SHA1 was deprecated, Sectigo (née Comodo) requested root stores
remove one of their roots [1], taking it out of scope for the BRs, and
continued issuing "legacy" SHA1 certificates off of that root. Sectigo
has also published a list of certificates containing underscores they
will be revoking [2]; conspicuously absent from that list are four of
these legacy SHA1 certificates [3].

Perhaps pilgrim2222's company (Verizon?) could convince a CA to do
something similar here?

Best,
Alex

[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1208461
[2]: https://misissued.com/batch/41/
[3]: https://crt.sh/?id=701056092, https://crt.sh/?id=700688392,
https://crt.sh/?id=701055930, https://crt.sh/?id=700688392
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to