Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Distrusting WoSign and StartCom Certificates #1359

Closed
ameshkov opened this issue Nov 1, 2016 · 4 comments
Closed

Distrusting WoSign and StartCom Certificates #1359

ameshkov opened this issue Nov 1, 2016 · 4 comments
Assignees
Labels
Milestone

Comments

@ameshkov
Copy link
Member

ameshkov commented Nov 1, 2016

https://security.googleblog.com/2016/10/distrusting-wosign-and-startcom.html

Certificates issued by WoSign and StartCom after October 21, 2016 00:00:00 UTC will not be trusted

@ameshkov ameshkov added this to the 6.1 R2 milestone Nov 1, 2016
@adbuker adbuker closed this as completed Nov 7, 2016
@ameshkov
Copy link
Member Author

Google Chrome does not trust ALL StartCom certificates starting from Chrome 57:
https://chromium.googlesource.com/chromium/src/+/e719fc626a3b9a528bf226b704785bcb24d07868

@ameshkov ameshkov reopened this Mar 12, 2017
@adbuker
Copy link

adbuker commented Mar 13, 2017

Will we check Alexa's rank for the website with "bad certificate", or not? if so, we can use their free Api for it (http://stackoverflow.com/questions/3676376/fetching-alexa-data)

@ameshkov ameshkov modified the milestones: 6.2, 6.1 R2 Mar 14, 2017
@ameshkov
Copy link
Member Author

We'd better wait for a month and then distrust all certs as well.

@adbuker
Copy link

adbuker commented Jul 27, 2017

resolved in ADWIN-CR-237

@adbuker adbuker closed this as completed Aug 1, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants