Re: it's all about trust [was: Firefox and HMC self-signed cert]

2023-08-29 Thread Grant Taylor
On 8/29/23 6:10 PM, Charles Mills wrote: Not browser publishers and CAs; ONE particular browser publisher! The CAs were on the other side of this one. Apple may have been the first to the microphone, but I know that other browser manufacturers were writing similar speeches. About the only

Re: it's all about trust [was: Firefox and HMC self-signed cert]

2023-08-29 Thread Charles Mills
Not browser publishers and CAs; ONE particular browser publisher! The CAs were on the other side of this one. https://www.zdnet.com/article/apple-strong-arms-entire-ca-industry-into-one-year-certificate-lifespans/ About the only thing I can say in their defense is that the revocation system is

Re: it's all about trust [was: Firefox and HMC self-signed cert]

2023-08-29 Thread Grant Taylor
On 8/29/23 2:49 PM, Rick Troth wrote: When they say "certificates shall only last a year", there's little we can do about it, whether they're right or wrong. The browser manufacturers have power in the browser ecosystem and the ecosystems that pander to them (*cough* CAs *couth*). But

it's all about trust [was: Firefox and HMC self-signed cert]

2023-08-29 Thread Rick Troth
On 8/29/23 11:24, Grant Taylor wrote: On 8/29/23 10:07 AM, Tom Brennan wrote: And you can specify an expiration far in the future. Remember, some web browsers are capping the limit on the lifetime of certificates they will work with. The browser producers have the advantage over the rest