Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting aside that came out of this case is the issue of cross-signing intermediary and root certs and it not being disclosed.

The WoSign roots were cross-signed by[0] Comodo and StartCom (owned by WoSign, but we didn't know that), so even with WoSign roots being revoked, there would still be a verification path.

Nice to see that now there is an effort to disclose all of these[2][3], and[1]:

> Mozilla now requires the disclosue of all intermedidate certificates, including those cross-certificates.

[0] https://wiki.mozilla.org/CA:WoSign_Issues#Cross_Signing

[1] https://groups.google.com/d/msg/mozilla.dev.security.policy/...

[2] https://crt.sh/mozilla-disclosures

[3] https://secure.comodo.com/products/publiclyDisclosedSubCACer...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: