5 ms·
Roots for all CAs are going to be rotating much more frequently now. Looking to be every 5 years.
by nickf 9mo ago
Roots for all CAs are going to be rotating much more frequently now. Looking to be every 5 years.
- michaelt 9mo agoI'd be interested in hearing more - do you have a source for this? Seems to me CAs have intermediate certificates and can rotate those, not much upside to rotating the root certificates, and lots of downsides.
- nickf 9mo agoChrome root policy, and likely other root policies are moving toward 5-years rotation of the roots, and annual rotation of issuing CAs. Cross-signing works fine for root rotation in most cases, unless you use IIS, then it becomes a fun problem.
- mikestorrent 9mo agoWhat an absolute pain in the ass for a mediocre increase in security.
- aaomidi 9mo agoThe upside to rotating roots is: 1. These might need to happen as emergencies if something bad happens 2. If roots rotate often then we build the muscle of making sure trust bundles can be updated I think the weird amount they are being rotated today is the real root cause if broken devices and we need to stop the bleed at some point.
- selcuka 9mo ago> If roots rotate often then we build the muscle of making sure trust bundles can be updated Five years is not enough incentive to push this change. A TV manufacturer can simply shrug and claim that the device is not under warranty anymore. We'll only end up with more bricked devices.
- michaelt 9mo ago> 1. These might need to happen as emergencies if something bad happens Isn't this the whole point of intermediate certificates, though? You know, all the CA's online systems only having an intermediate certificate (and even then, keeping it in a HSM) and the CA's root only being used for 20 seconds or so every year to update the intermediate certificates? And the rest of the time being locked up safer than Fort Knox?
- aaomidi 9mo agoThe thing is even the most secure facilities need ingress and egress points. Those are weaknesses. It’s also that a root rotation might be needed for completely stupid vulnerabilities. Like years later finding that specific key was generated incorrectly.
- silverwind 9mo agoSounds like planned obsolescence if devices stop working after 5 years or less.
- majewsky 9mo agoOnly for devices that do not allow you to patch the CA bundle as an aftermarket repair. Call your representative and demand Right to Repair legislation.
- aftbit 9mo agoThat is ... basically all of them? Other than general purpose desktop/laptop computers that is. Show me a TV or smartphone that does allow you to push new roots to it...