oh, yeah, totally clicking on that.
oh, yeah, totally clicking on that.
DoD today, UK MOD tomorrow, Russia and China when?
Private/Internal/Enterprise CA's are intentionally out of the ring of trust for SSL certificates, there is no need to give the DoD any preferential treatment.
This would literally benefit no one as anyone with any interest in accessing those websites would install the certificate.
US .gov sites are "secured" with commercial CA certificates so they aren't even part of the argument.
When you count the benefit / usefulness of this change which is very little to null and compare it to the possibility of it being abused as well as the precedent of adding "internal" certificate authorities to the global trust list I see a pretty solid argument against this.
Overall with things like LetsEncrypt I hope that the CA/SSL Cert industry would get disrupted enough for most if not all commercial CA's to simply become irrelevant.
It's not a question of insurance rather than a technical issue since you still get an 'n' figures "fraud" insurance when you purchase validated SSL certificates from commercial CA's and some standards require you to use them rather than LE and the likes.
To my knowledge I do not know of any case on which that insurance has ever been successfully claimed so this entire premise should be just killed off completely.
'LE' and similar services should then be managed by a non-profit or a handful of those maybe for each region and just be done with it, the CA list is already too big and it's already near impossible to figure out who owns what besides the <10 big players.
I honestly see no reason for SSL to work a browser have to have a list of 130-150 CA's on file (default Root+Intermediate CA listing on Windows).
https://www.ssllabs.com/ssltest/analyze.html?d=spi.dod.mil&s...
http://iase.disa.mil/pki-pke/Documents/unclass-installroot_v...
There are (impressively thorough, including recommendations on out-of-band fingerprint authentication) installation instructions included, and they provide PEM, PKCS7, and some weirdo Windows format.
Alternatively, the DoD certs served up securely by Symantec: https://knowledge.symantec.com/support/eca-support/index?pag...
So, programs are downloading certs automatically, where they would be even less likely to properly check checksums against a secure site. And create a additional small attack vector.
Well, also because an HTTPS page would create a chicken-and-egg situation. How do you download the root certs if you can't see the page because you don't have the root certs? etc
We have almost zero control over the webserver; it's run by a completely separate group of people. We can change some of the content, but next to nothing of the server config itself.
(I realize that may sound strange to those of you who have never worked with any DoD organizations. Imagine going to one of the largest bureaucracies on the planet and saying, "We want you to change something.")
So yeah, none of us are happy about the current situation. Trying to distribute security-oriented software via a website with a SHA-1 cert signed by a root cert that has to be installed separately... the irony is nearly poetic.
Hoping to move to a completely different web host (still DoD, just different) before the end of the year. Most of us would be like, "we could do that in a day, plus DNS TTL expirations," but when they're not actually in combat, the DoD moves at... well, they move at the speed of government! :-)
The whole site is a joke, but then again, so are most US govt sites. I don't understand why they have to keep using ugly, outdated and badly operating websites over there.
The beauty of Twitter Bootstrap is that good get a modern responsive website with less work than rolling your own design, or even having to think about it.