Mozilla网络安全SSL 证书数字证书Wosign 沃通

如何看待 Mozilla 决定停止信任沃通 (WoSign) 和 StartCom 颁发的证书?

问题描述

'Taking into account all the issues listed above, Mozilla’s CA team has lost confidence in the ability of WoSign/StartCom to faithfully and competently discharge the functions of a CA. Therefore we propose that, starting on a date to be determined in the near future, Mozilla products will no longer trust newly-issued certificates issued by either of these two CA brands.'
docs.google.com/documen

Solidot | Mozilla表态将停止信任WoSign 和StartCom签发的新证书
Mozilla 公布了对沃通CA不当行为的13页调查报告,正式提议将停止信任 WoSign 和 StartCom 签发的新证书,最短期限为一年,一年之后如果 WoSign 和 StartCom 能满足条件 Mozilla 可以再次接纳它们。
调查报告称,沃通 CA 存在的部分问题不严重或不是它的过错,但还有部分问题极其严重,从信任角度看最严重的问题是故意倒填证书日期绕过浏览器对 SHA-1 证书的限制。由于 SHA-1 签名证书不再安全,主要浏览器开发商要求所有 CA 在 2016 年1月1日之后停止签发 SHA-1 证书,然而沃通 CA 在 2016年1月1日之后仍然签发了 SHA-1 证书,通过故意倒填日期,将这些证书伪装成是在 2016 年前签发的。另一个问题是 WoSign 收购 StartCom ,即使有充足的证据证明WoSign CA 已经100%收购 StartCom CA,公司 CEO 王高华仍然拒绝承认,直到最后 WoSign 的母公司奇虎 360 现身才予以承认,但王高华又坚称 StartCom 独立运营,其原始系统没有发生改变,然而有充分的技术证据证明 StartCom 在被收购一个半月后,它就开始使用 WoSign 的基础设施签发证书。StartCom 的网站 StartSSL.com 在 2015年12月18日关闭升级系统,到 12月22日重新开放时它就切换到了 WoSign 的系统。
相关问题:
如何看待中国沃通wosign偷偷收购自己的根CA startcom并且签发github.com的证书? - 信息安全
如何看待沃通证书销售发垃圾邮件黑Let's Encrypt? - SSL
地铁风
不会撸程序的设计狮不是好科研狗

看了 Mozilla 的文档,我就补充一点,文档里提到:

In our policy newsgroup, WoSign proposed that an appropriate response to this list of issues (or the subset of them known at the time they made their proposal, which did not include any of the SHA-1 backdating information) would be to constrain them to issuing in the China market only in future. However, we don’t feel that Mozilla’s users in China have lower requirements for CA trustworthiness than Mozilla’s users elsewhere.

简单说就是

WoSign: 我们不靠谱没关系,你只让我在中国签证书就行。

Mozilla: 滚。


广大网民差点就这么被这个傻逼公司卖了,幸好 Mozilla 规矩严明。

159 赞同 17 感谢 15 收藏 9 条已备份评论 发布于 2016-09-27 知乎原页 ↗

评论 9

中国公司主动歧视中国人…简直丢人丢到国际上去了
71 赞
Mac里有startcom的root ca证书,然后startcom和wosign交叉签署了root ca,所以照说是不会报cannot verify identity的。我的Mac就没报。
3 赞
地铁风回复 杨垒作者
噢,是因为我禁用了 start com 的证书。
1 赞
Mac自己手动Never Trust Start Com。需要注意的是:如果之前已经Never Trust了StartCom,在更新Sierra后,StartCom的证书信任会重置为信任。不清楚这是苹果有意重置所有证书信任关系,还是bug。
4 赞
知乎用户L3dLgb
刚刚删除了wosign、certum、startcom的根证书。
9 赞