Improved Digital Certificate Security
googleonlinesecurity.blogspot.com
googleonlinesecurity.blogspot.com
HTTPS Everywhere makes the page blank (at least it did for me).
If any of you guys read this, send me a message. I'm not in a position to hire anyone, but I'm working out the details of a non-profit service that could use your expertise or advice.
And what kind of CA doesn't blacklist high-value domains like Google, PayPal, etc. so that they don't get screwed over in this manner?
Google noticed this when it showed up in Certificate Transparency logs, and Symantec asserted it was created during internal testing of their systems.
For anybody else who didn't know what a "pre-certificate" was, https://tools.ietf.org/html/rfc6962#section-3.1 :
Anyone can submit a certificate to any log. In order to enable
attribution of each logged certificate to its issuer, the log SHALL
publish a list of acceptable root certificates (this list might
usefully be the union of root certificates trusted by major browser
vendors). Each submitted certificate MUST be accompanied by all
additional certificates required to verify the certificate chain up
to an accepted root certificate. The root certificate itself MAY be
omitted from the chain submitted to the log server.
Alternatively, (root as well as intermediate) certificate authorities
may submit a certificate to logs prior to issuance. To do so, the CA
submits a Precertificate that the log can use to create an entry that
will be valid against the issued certificate.