6 ms·
Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few year
by naraniano 9y ago
Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few years ago, and I'm not sure how these things are standardised.
- owenmarshall 9y agoStandardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking-mandatory/ https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...
- naraniano 9y agoAh, so they are three days late. That doesn't sound too serious.
- scaryclam 9y agoThree days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.
- mynameisvlad 9y agoThree days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.
- gus_massa 9y agoThe ballot was in March, so they have 6 month to prepare for it, not only 3 days to implement a surprising change.
- Karunamon 9y agoExcept they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.
- mynameisvlad 9y agoThat makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.
- mannykannot 9y agoKarunamon et. al. are not saying your point is wrong; they are saying it is irrelevant, and if their facts are correct then they are right.
- mtgx 9y agoIt's not about them being late these 3 days. It's about them lying about having already implemented this months ago.
- naraniano 9y agoHow do you know they lied? What if they implemented it but simply did not flip the switch?
- mannykannot 9y ago'Lie' is indeed a strong term, informally suggesting an intent to deceive. Personally, I would suspect negligence and incompetence rather than deceit, but negligence is a serious matter here.
- Karunamon 9y agoGiven the general crappiness of the CA industry, my first instinct is to say they willfully said "yeah we support it" without actually doing it first, knowing that it wasn't actually done.
- wbl 9y agoThese 3 days don't matter when you have months of lead time.
- tinus_hn 9y agoOn a requirement they voted for half a year ago for a standard specified 5 years ago. It's sloppy and sloppy is not a property you want in a certificate authority.
- Kalium 9y agoFrom experience working with them, sloppy is an excellent way to describe Comodo.
- mtgx 9y agoI wonder about what else is Comodo being "not too serious" while they promise to be "super serious" about them in their marketing campaigns?
- agwa 9y ago> Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? CAA was made up by... drumroll.... Comodo. Yes, check the authors on the RFC: https://tools.ietf.org/html/rfc6844 https://tools.ietf.org/html/rfc6844