全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

IP归属甄别会员请立即修改密码
查看: 1416|回复: 9
打印 上一主题 下一主题

塞门铁壳SSL出事了?

[复制链接]
跳转到指定楼层
1#
发表于 2017-3-25 08:46:41 来自手机 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
Google has recently identified a series of failures by Symantec Corporation to properly validate certificates, and as a result, Google has stated its intent (https://groups.google.com/a/chromium.org/forum/#%21topic/blink-dev/eUAKwjihhBs) to take the following steps relating to the Chrome browser:
* Reduce the maximum accepted validity period of newly-issued Symantec certificates to nine months or less

* Implement a rolling distrust of all currently-trusted Symantec-issued certificates, forcing the certificates to be replaced with new certificates before the original would expire

* Remove the EV (Extended Validation) treatment of Symantec EV certificates for at least the next year

Since Google Chrome has a majority of the browser market, this will have a significant impact on the industry and potentially on your web assets.

In an effort to protect the safety of internet users, avoid disruption, and minimize the management burden to you, Comodo will help all affected Symantec, Thawte and Geotrust customers. Comodo will replace the remaining lifetime on your existing Symantec/Thawte/Geotrust certificates at no cost (example: a three-year certificate with two years remaining can be replaced with a three-year Comodo certificate for the cost of one year).

Please call 1-855-478-7740 or contact [email protected] (mailto:[email protected]?
10#
发表于 2017-3-25 12:50:17 | 只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
9#
 楼主| 发表于 2017-3-25 12:46:20 | 只看该作者
tension 发表于 2017-3-25 12:38
GeoTrust 肯定没事。。。


我看有事。
https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md
除了这些没事。其他由赛门铁克控制的私钥都出事, 本来是没事。
As discovered during the follow-up of a previous incident - https://security.googleblog.com/2015/10/sustaining-digital-certificate-security.html - Symantec has cross-signed two organizations who operate wholly independent infrastructure that is audited as such - Apple and Google. This is documented at https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md

As such, these certificates are not "Symantec-issued", for any reasonable definition, and are effectively operated by independent third parties, and thus would be proposed to be excluded from these requirements.

This evaluation of trust is not based upon an intrinsic property, but on the public disclosure and ability to independently confirm and assess the policies and practices related to issuance by these two parties.

All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding.

While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md may accurately capture the state of impact
8#
发表于 2017-3-25 12:38:28 | 只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
7#
 楼主| 发表于 2017-3-25 12:23:04 | 只看该作者
tension 发表于 2017-3-25 12:08
只有 EV 出事了!

GeoTrust 应该没事。
google自己也在用
6#
发表于 2017-3-25 12:08:16 | 只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
5#
发表于 2017-3-25 11:36:26 | 只看该作者

哼,我不信
4#
发表于 2017-3-25 08:49:47 | 只看该作者
http://www.ithome.com.tw/news/112989
跟當初誤發了Goolge的憑證延燒到現在,被發現誤發超過3萬的憑證

賽門鐵克2015年誤發逾3萬個憑證,Google祭制裁:Chrome逐步不再承認其憑證
賽門鐵克在2015年坦承誤發Google.com延伸驗證憑證,Google追查後發現誤發數量超過3萬個,本周對賽門鐵克祭出制裁,未來將透過Chrome的版本升級逐漸廢止賽門鐵克旗下憑證機構簽發的現有憑證。
3#
发表于 2017-3-25 08:48:40 | 只看该作者
感覺在推銷comodo
2#
发表于 2017-3-25 08:47:31 | 只看该作者
什么鬼  炸裂啊
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2025-9-30 05:05 , Processed in 0.066209 second(s), 9 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表