Re: [therightkey] [cabfpub] Updated Certificate Transparency + Extended Validation plan

michal.proszkiewicz@unizeto.pl Wed, 05 February 2014 16:19 UTC

Return-Path: <michal.proszkiewicz@unizeto.pl>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BAC371A0132 for <therightkey@ietfa.amsl.com>; Wed, 5 Feb 2014 08:19:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.651
X-Spam-Level:
X-Spam-Status: No, score=0.651 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_PL=1.135, HOST_EQ_PL=1.95, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.535] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T4EeVPMZasdX for <therightkey@ietfa.amsl.com>; Wed, 5 Feb 2014 08:19:47 -0800 (PST)
Received: from mail.unizeto.pl (mail.unizeto.pl [213.222.192.4]) by ietfa.amsl.com (Postfix) with ESMTP id 164C91A00EE for <therightkey@ietf.org>; Wed, 5 Feb 2014 08:19:46 -0800 (PST)
Received: from lotus.unizeto.pl ([192.168.128.14]) by f-secure.unizeto.pl (8.14.5/8.14.5) with ESMTP id s15GJdIV013351; Wed, 5 Feb 2014 17:19:39 +0100
In-Reply-To: <CAL9PXLzCqvBGW=Du9ZAdMXiVgcO8WJHXf+wG7EuzE2246TFEmg@mail.gmail.com>
To: agl@chromium.org
MIME-Version: 1.0
X-Mailer: Lotus Notes Release 7.0.3 September 26, 2007
Message-ID: <OF51410A26.69287B04-ONC1257C76.0058AE9E-C1257C76.0059B04A@unizeto.pl>
From: michal.proszkiewicz@unizeto.pl
Date: Wed, 05 Feb 2014 17:19:38 +0100
X-MIMETrack: Serialize by Router on HUB/UNIZETO(Release 7.0.3FP1|February 24, 2008) at 2014-02-05 17:19:39, Serialize complete at 2014-02-05 17:19:39
Content-Type: multipart/alternative; boundary="=_alternative 0059B047C1257C76_="
X-Mailman-Approved-At: Fri, 07 Feb 2014 08:05:52 -0800
Cc: therightkey@ietf.org, public-bounces@cabforum.org, certificate-transparency@googlegroups.com, public@cabforum.org
Subject: Re: [therightkey] [cabfpub] Updated Certificate Transparency + Extended Validation plan
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey/>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Feb 2014 16:21:24 -0000

If we are talking about EV certificates then probably there are not many 
that are valid for a 1 month.

It may be the case for other types of certificates. For example CERTUM 
issue trusted test SSL certificates valid for 30 days (standard DV 
verification procedures and DV certificate profile).

>From the other hand we give our customer possibility to manually shorten 
validity period to one day if they like (for every certificate type).

-Michał




Adam Langley <agl@chromium.org> 
Wysłane przez: public-bounces@cabforum.org
2014-02-05 16:40

Do
certificate-transparency <certificate-transparency@googlegroups.com>
DW
"therightkey@ietf.org" <therightkey@ietf.org>, CABFPub 
<public@cabforum.org>
Temat
Re: [cabfpub] Updated Certificate Transparency + Extended       Validation 
plan






On Wed, Feb 5, 2014 at 10:26 AM, Rob Stradling <rob.stradling@comodo.com> 
wrote:
> Also, what happened to the idea of only requiring 1 SCT for a 1-month 
cert?

I'm to blame for that.

Certificates with a single SCT put a lower bound on how quickly we can
distrust a log (at least without special measures, such as shipping
the whole, public log hashes to all the clients, which is probably
impractical.) Since I'm not aware of any CAs issuing one month certs,
and it only saves ~100 bytes vs 2 SCTs, it seemed to be something that
should be dropped.


Cheers

AGL
_______________________________________________
Public mailing list
Public@cabforum.org
https://cabforum.org/mailman/listinfo/public