Re: [TLS] Eleven out of every ten SSL certs aren't valid

aerowolf@gmail.com Wed, 30 June 2010 21:08 UTC

Return-Path: <aerowolf@gmail.com>
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 943943A6B17 for <tls@core3.amsl.com>; Wed, 30 Jun 2010 14:08:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.78
X-Spam-Level:
X-Spam-Status: No, score=-0.78 tagged_above=-999 required=5 tests=[AWL=0.264, BAYES_00=-2.599, HTML_MESSAGE=0.001, HTML_MIME_NO_HTML_TAG=0.097, MIME_HTML_ONLY=1.457]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mWdPS4G9ochy for <tls@core3.amsl.com>; Wed, 30 Jun 2010 14:08:38 -0700 (PDT)
Received: from mail-pv0-f172.google.com (mail-pv0-f172.google.com [74.125.83.172]) by core3.amsl.com (Postfix) with ESMTP id 948B93A6873 for <tls@ietf.org>; Wed, 30 Jun 2010 14:08:38 -0700 (PDT)
Received: by pvd12 with SMTP id 12so689943pvd.31 for <tls@ietf.org>; Wed, 30 Jun 2010 14:08:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:from:to:cc:date:message-id :subject:mime-version:content-type; bh=7dxx82PSCHjarH025qXP67G46TcSDg43RUfP67qbUA4=; b=dYVZyDUC/me/iyVxBPkcJO+uL03hxKbyYhwOLfm5YgnW/FfMh5nx69MP1X3D4zKVsT furRjNFxpxEV0lUUix3AhyP7TbwXWPH2rEWYV4c13yYUHeyTakOPNaVMiA93c5DlnRga A1OextBDQu8b8mDhEEoH3qhmWnCgcLZRrM8T0=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=from:to:cc:date:message-id:subject:mime-version:content-type; b=xcT8vzZ0lTyJDLxc8qvQ2gLOlK01foMDE3V1E3XcFrs+DcknBG54cxvQwl8rhOjWZ+ F4LGhmjotSooy0snSwB+nkC8//roeUOjfmJY3p90be3OajUFwbGag+81deAcjFEVyL0S /E3vILIh79CKQT75K8tHMYLd9AKtWCZRumFOk=
Received: by 10.142.10.5 with SMTP id 5mr11133374wfj.267.1277932126503; Wed, 30 Jun 2010 14:08:46 -0700 (PDT)
Received: from [127.0.0.1] (c-76-103-146-6.hsd1.ca.comcast.net [76.103.146.6]) by mx.google.com with ESMTPS id e32sm5959455wfj.15.2010.06.30.14.08.44 (version=SSLv3 cipher=RC4-MD5); Wed, 30 Jun 2010 14:08:45 -0700 (PDT)
From: aerowolf@gmail.com
To: Joshua Davies <joshua.davies@travelocity.com>
Date: Wed, 30 Jun 2010 14:08:35 -0700
Message-ID: <gb2nsbd7zdhn30iyccJYNxe982v3j_gmsm@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha1"; boundary="gmsm0.4.7eqgb2nshwezsblf0hckr2"
Cc: tls@ietf.org
Subject: Re: [TLS] Eleven out of every ten SSL certs aren't valid
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jun 2010 21:08:39 -0000



On Tue, Jun 29, 2010 at 8:43 AM, Joshua Davies <joshua.davies@travelocity.com> wrote:
Well, ok, but... why listen on port 443 if you don't plan to support SSL in the first place?  I doubt that http://oracle.com" target="_blank" rel="nofollow">oracle.com is being run from a shared-hosting site.  Most likely it's Akamai that's doing something that doesn't mix well with TLS; Oracle may not care, but this, I would think, would be of some interest to the IETF TLS working group...

Does it matter if someone decides to use 443 for a purpose other than HTTP with TLS/SSL transport?

And besides, the entire concept of "valid certificates" isn't exactly one for tls@ietf.org, it's one for pkix@ietf.org.  The people who have created a protocol which has a mode where neither party authenticates itself should not be held liable for sites that choose not to authenticate themselves in a manner based on an *informational* RFC.

-Kyle H