Re: [wpkops] draft-housley-web-pki-problems-00

Gervase Markham <> Wed, 08 July 2015 11:15 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id E5D2A1B3465 for <>; Wed, 8 Jul 2015 04:15:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id C08-3nG_T1-D for <>; Wed, 8 Jul 2015 04:15:20 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 07E401B343B for <>; Wed, 8 Jul 2015 04:15:19 -0700 (PDT)
Received: by wiga1 with SMTP id a1so281900353wig.0 for <>; Wed, 08 Jul 2015 04:15:18 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20130820; h=x-gm-message-state:subject:to:references:from:openpgp:message-id :date:user-agent:mime-version:in-reply-to:content-type :content-transfer-encoding; bh=kYd5EdHcSEjcyQMAK9IctDwfswAfFHT7ZP2l+gwSU3Y=; b=TkjNTtcdc416O++pJpGgqU7voBW7XSlLG6RRoeQ32JiUISX4hcn9AhzOehNI7ivZbi c+ShmkWi0crj4QSuKQjw80J0m1wHyDwYD3PVT7gIwe3f6iLD9I0mMVorRxBl7k3Yykg/ snazzeLkkM3BsCDMLaTDSNPoSUxr4/vK6hhdkV4n5fwdlu5dffuU0E/yyNmb3C3YFlKQ Lw0ot5AYo3qb6yP+FDxJBud87GZ0L38+o7tVO0OlIBf0vI83BW7EVD81uqbWksaMn+VD d5xicEG0MKuptmnDlo1mNJ2ckU8eRoQ+ZW3KlRxRhS8KK4RHF/A2BDUBwuKBRleU7VTS GTqg==
X-Gm-Message-State: ALoCoQlbOPju+BBCnIPYKfcu+lnSU8ZaMQMH+IBM6CyqDCo/aZYFnc7W5lsprkQyMiOt60L84vmE
X-Received: by with SMTP id r19mr115255423wiw.9.1436354118605; Wed, 08 Jul 2015 04:15:18 -0700 (PDT)
Received: from [] ( []) by with ESMTPSA id c11sm2736086wib.1.2015. for <> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 08 Jul 2015 04:15:17 -0700 (PDT)
References: <>
From: Gervase Markham <>
Openpgp: id=EEDEEFF962E97696DACBD2CCD9B347EA9DF43DBB
X-Enigmail-Draft-Status: N1110
Message-ID: <>
Date: Wed, 8 Jul 2015 12:15:16 +0100
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:38.0) Gecko/20100101 Thunderbird/38.0
MIME-Version: 1.0
In-Reply-To: <>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: <>
Subject: Re: [wpkops] draft-housley-web-pki-problems-00
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 08 Jul 2015 11:15:23 -0000

On 07/07/15 15:57, Russ Housley wrote:
> I want to make people on this list aware of this draft that was posted yesterday.
> Stephen Farrell suggested that this list might be a good place to discuss it.

Some comments:

3.1: See:

3.2/3.3: See HPKP, CAA and CT.

3.4: Bug Apple :-)

3.5: See Let's Encrypt, DigiCert Express Install, SSLMate etc. etc.

3.6: The entire point of Trustwave is that browsers could _not_
ordinarily detect the MITM. But anyway: it has been suggested that MITM
certs should be required to have a special marking which browsers can
detect, but this solution, when investigated, has a number of problems.
Ideas welcome.

3.7: 1024-bit: See
for roots, CAB Forum policy for intermediates and EE certs. SHA1: See
Microsoft and Google policy and CAB Forum policy. MD5 is already dead.
RC4 is being worked on: see .

4.1: With regard to the Mozilla root program, I refute the first
suggestion here. See and many other

4.2: The actions we took in the CNNIC case were specifically designed to
be generalisable to a CA otherwise considered "too big to fail".

4.3: Given the existence of the above-mentioned services and APIs, this
seems like a Simple Matter of Programming to me. :-)

5.1.1: Browsers don't use such extensions because CRLs suck.

5.1.2: Indeed. Please put polite pressure on the Apache project and/or
Linux distributions to allow OCSP stapling to be enabled by default.

5.2.1: See .

5.2.2: CAA is fine.

6.1: The CAB Forum is a lot more open, inclusive and transparent than it
once was, in part due to Mozilla pressure. For example, voting is no
longer secret, and nor are the mailing lists. Third parties can now take
part (although not vote) in working groups. Organizations can become
associate members. And while this is not full openness and transparency, is always open to hear input from the
Internet community on what Mozilla should be doing or advocating.

The chances of browser makers handing over the right of decisions about
who to trust to a 3rd party body are vanishingly small.