{"id":4015,"date":"2017-05-02T16:09:33","date_gmt":"2017-05-02T20:09:33","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=4015"},"modified":"2018-09-27T06:56:53","modified_gmt":"2018-09-27T10:56:53","slug":"mozilla-symantec-proposal","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/mozilla-symantec-proposal\/","title":{"rendered":"Mozilla Posts Proposal for Action Against Symantec"},"content":{"rendered":"<h2>Mozilla will make a final decision on Symantec in a week\u2019s time.<\/h2>\n<p>On Monday, Mozilla <a href=\"https:\/\/groups.google.com\/forum\/#!topic\/mozilla.dev.security.policy\/IZYmm8zsSKU\">released a 10-page report<\/a>. This report includes both an in-depth summary of the events and issues so far, as well as a draft version of their response.<\/p>\n<p>For those who want to quickly catch up, this entire saga has become extremely complicated since Google <a href=\"https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!topic\/blink-dev\/eUAKwjihhBs%5B1-25%5D\">posted their original proposal on March 23<sup>rd<\/sup><\/a>.<\/p>\n<p>The key events since then: Google and Mozilla publicly investigated the issues, finding more evidence of poor management. Both companies then agreed to give Symantec time to provide their own counter-proposal (a \u201cremediation plan\u201d) for handling the issues, <a href=\"https:\/\/community.digicert.com\/en\/blogs.entry.html\/2017\/04\/27\/symantec-ca-response-to-google-proposal-and-community-feedback.html\">which they did last week<\/a>. Google then provided a <a href=\"https:\/\/groups.google.com\/forum\/#!msg\/mozilla.dev.security.policy\/lOHrTr97Qx0\/2IkcSGq9AQAJ\">counter-counter-proposal<\/a>.<\/p>\n<p>That counter-counter-proposal, penned by Google\u2019s Ryan Sleevi, was sent to Symantec in mid-April and parts of it were publicly shared last week. It suggested Symantec partner with another CA, \u201cthereby removing Symantec infrastructure and validation processes from the equation.\u201d<\/p>\n<p>In the future, Symantec could then acquire this CA, or its roots, and bring issuance and validation back under its roof. The specific conditions for this were not detailed.<\/p>\n<p>While this is a radical suggestion, Sleevi noted that it would \u201cmitigate our primary concerns related to new certificates,\u201d eliminating the need to place restrictions on new Symantec SSL certificates.<\/p>\n<p>Because all new Symantec certificates would be handled by a separate PKI infrastructure, it would give browsers complete confidence that mistakes related to the existing infrastructure were eliminated. Existing certificates would still need to be dealt with, but this would essentially provide a clean start for Symantec\u2019s CA.<\/p>\n<p>In today\u2019s report, Mozilla said that they too think this is the best way forward for Symantec and are urging the company to consider it. Mozilla also proposed a fall-back if Symantec decides not to \u2018restart\u2019 their PKI.<\/p>\n<p>They key details of this proposal are:<\/p>\n<ul>\n<li>Symantec must provide Mozilla with a \u201cfull PKI diagram\u201d of all roots and sub-CAs that are trusted by Mozilla. All the certificates involved with non-compliant issuance must be revoked.<\/li>\n<li>New Symantec certificates will be limited to 13-month validity.<\/li>\n<li>Existing Symantec certificates will be gradually restricted to 13 months of validity.<\/li>\n<\/ul>\n<p>Note that these restrictions only occur if Symantec decides to continue operating under its existing PKI infrastructure.<\/p>\n<p>Notably, the Mozilla Symantec proposal does not involve removing Symantec\u2019s EV status (Google\u2019s proposed plan does). Its report states \u201cthe risk has now been eliminated, and no existing Symantec EV certificates are affected. Therefore\u2026 the removal of EV status seems unwarranted.\u201d<\/p>\n<p>So far, none of the root programs have officially committed to a plan, but that will happen soon. Mozilla has said that it will release a final decision on May 8<sup>th<\/sup>, and are <a href=\"https:\/\/groups.google.com\/forum\/#!topic\/mozilla.dev.security.policy\/IZYmm8zsSKU\">accepting public comments in this thread<\/a> until then. Google\u2019s proposal is still being internally considered, with no known deadline. Apple and Microsoft have been entirely quiet during this entire situation \u2013 which is normal.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mozilla will make a final decision on Symantec in a week\u2019s time. On Monday, Mozilla released a 10-page report. This report includes both an in-depth summary of the events and&#8230;<\/p>\n","protected":false},"author":2,"featured_media":4018,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[164,192,581,467,139,362],"class_list":["post-4015","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-certificate-authorities","tag-mozilla","tag-ssl-certificate","tag-ssltls","tag-symantec","tag-trust","post-with-tags"],"views":7134,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/mozilla-firefox-symbol-hq-headquarters-building-sign-symbol-convention-open-source-1200x630-c.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4015","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=4015"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4015\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/4018"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=4015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=4015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=4015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}