A critical Windows component expires in 25 hours
hexatomium.github.io
hexatomium.github.io
The last high-profile mis-issued cert was last week, and didn't even escape the control of people who were entrusted with the CA private key. So MS might not even be manually revoking it. Before that, the last blog post on googleonlinesecurity.blogspot.com about a mis-issued certificate was ... March 23.
I would guess that it's re-signed daily, but only changes when there's an actual change to be made.
There's a reference to the date 150923203626Z (2015-09-23 20:36:26 UTC) somewhere in there, but I'm having trouble figuring out what it applies to.
apt, yum, PGP, etc. work the same way. There remains a decent argument for a secure transport anyway for privacy / avoiding side channels, or a general desire for HTTP delenda est, but it's nowhere near as strong an argument, HTTPS only provides marginal benefit to the side channels (Tor to a hidden service is much more effective), and other engineering concerns can legitimately override these concerns.
True, but it might be slightly less visible because you'd get an "update" instead of a failure. Also, I wonder if anyone has actually tested that scenario?
I'd like to believe that's true and that should be true, but I'd also have to actually test it before trusting it to be true.
Set the clock forward and see?
[1] https://azure.microsoft.com/en-us/blog/windows-azure-service...
Edit:
ListIdentifier = "DisallowedCert_AutoUpdate_1"
SequenceNumber = 01d0f584a9ad12f7
ThisUpdate = "23.09.2015 00:18"
NextUpdate = LEER
SubjectAlgorithm = 1.3.6.1.4.1.311.10.11.15, "disallowedHash"
SignerExpiration = "14.08.2016 19:13", "326,3 Days"
CTLEntries = 57
Das System kann die angegebene Datei nicht finden. 0x80070002 (WIN32: 2 ERROR_FI LE_NOT_FOUND) -- http://ctldl.windowsupdate.com/msdownload/update/v3/static/t... tedr/en/disallowedcertstl.sst
MissingCerts = 57
yesterday it told me that it wasn't updated since 180 days.
Edit: Confirmed! Blog post updated.
https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
Microsoft Windows [Version 10.0.10240]
(c) 2015 Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32>certutil -verifyCTL disallowed
LastSyncTime = "22/09/2015 13:53"
[DisallowedCTL]
ListIdentifier = "DisallowedCert_AutoUpdate_1"
SequenceNumber = 01d065c00c3f1258
ThisUpdate = "24/03/2015 00:21"
NextUpdate = EMPTY
SubjectAlgorithm = 1.3.6.1.4.1.311.10.11.15, "disallowedHash"
SignerExpiration = "23/09/2015 21:36", "1.0 Days"
WARNING = "SignerExpiration: Less than 180 Days"
CTLEntries = 57
The system cannot find the file specified. 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND) -- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcert.sst
MissingCerts = 57
but I know nothing about the implications. It also looks like the file has the possibility to be downloaded from msft on the fly? > certutil -verifyCTL disallowed
LastSyncTime = "9/22/2015 9:33 AM"
[DisallowedCTL]
ListIdentifier = "DisallowedCert_AutoUpdate_1"
SequenceNumber = 01d065c00c3f1258
ThisUpdate = "3/23/2015 6:21 PM"
NextUpdate = EMPTY
SubjectAlgorithm = 1.3.6.1.4.1.311.10.11.15, "disallowedHash"
SignerExpiration = "9/23/2015 3:36 PM", "1.0 Days"
WARNING = "SignerExpiration: Less than 180 Days"
CTLEntries = 57
The system cannot find the file specified. 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND) -- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcert.sst
MissingCerts = 57 (endpoint) C:\Users\orf
λ certutil -verifyCTL disallowed | head
LastSyncTime = "22/09/2015 18:24"
[DisallowedCTL]
ListIdentifier = "DisallowedCert_AutoUpdate_1"
SequenceNumber = 01d065c00c3f1258
ThisUpdate = "24/03/2015 00:21"
NextUpdate = EMPTY
SubjectAlgorithm = 1.3.6.1.4.1.311.10.11.15, "disallowedHash"
SignerExpiration = "23/09/2015 21:36", "1.0 Days"
WARNING = "SignerExpiration: Less than 180 Days"
CTLEntries = 57
Then a whole load of entries like: [f69d22ae1ed615b1b9e390e310bbbb31]
CertId = 1.3.6.1.4.1.311.10.11.0
Subject = "MISSING_CERTIFICATE" C:\Users\gapinski>certutil -verifyCTL disallowed|more
LastSyncTime = "9/23/2015 3:33 AM"
[DisallowedCTL]
ListIdentifier = "DisallowedCert_AutoUpdate_1"
SequenceNumber = 01d0f584a9ad12f7
ThisUpdate = "9/22/2015 6:18 PM"
NextUpdate = EMPTY
SubjectAlgorithm = 1.3.6.1.4.1.311.10.11.15, "disallowedHash"
SignerExpiration = "8/14/2016 1:13 PM", "326.4 Days"
CTLEntries = 57
…Do you have a source? As far as I know that is not accurate.
Apple has App Transport Security which allows you to require CT. I think the OP meant Google, as the patch[1] for CT is still pending in Firefox.