Interesting aside that came out of this case is the issue of cross-signing intermediary and root certs and it not being disclosed.
The WoSign roots were cross-signed by[0] Comodo and StartCom (owned by WoSign, but we didn't know that), so even with WoSign roots being revoked, there would still be a verification path.
Nice to see that now there is an effort to disclose all of these[2][3], and[1]:
> Mozilla now requires the disclosue of all intermedidate certificates, including those cross-certificates.
The WoSign roots were cross-signed by[0] Comodo and StartCom (owned by WoSign, but we didn't know that), so even with WoSign roots being revoked, there would still be a verification path.
Nice to see that now there is an effort to disclose all of these[2][3], and[1]:
> Mozilla now requires the disclosue of all intermedidate certificates, including those cross-certificates.
[0] https://wiki.mozilla.org/CA:WoSign_Issues#Cross_Signing
[1] https://groups.google.com/d/msg/mozilla.dev.security.policy/...
[2] https://crt.sh/mozilla-disclosures
[3] https://secure.comodo.com/products/publiclyDisclosedSubCACer...