Announcing https://GitHub.com/RedHatProductSecurity/Certificates-Shipped/
seclists.org
seclists.org
Announcing https://github.com/RedHatProductSecurity
/Certificates-Shipped/ From: Kurt Seifried
<kseifried () redhat com>
Date: Tue, 24 Nov 2015 21:38:35 -0700
[1] https://github.com/RedHatProductSecurity/
Certificates-Shipped/
The idea is to create a comprehensive list of
shipped certs/keys/etc by open source
vendors/distributions/projects so that:
1) we have a list of secrets maintained by
external parties that we rely upon
2) we can audit them and make sure we
should be trusting them
3) also spot changes more easily (since the
existing corpus is available)
I'm guessing there are some surprises
waiting for us.
--
Kurt Seifried -- Red Hat -- Product Security
(...)
[1] Split to avoid long unbreakable line in pre-text-box on hn:https://github.com/RedHatProductSecurity/Certificates-Shippe...