Sounds very generous to me.
Sounds very generous to me.
StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, it would primarily punish StartCom's customers, and not WoSign, which as a business is primarily concerned with forward revenue.
You see this as leniency, but I see it as a powerful step forward. The browsers and CAs had previously been locked in a Mexican Standoff, with abusive CAs fully aware of the leverage their userbases offered them.
That's a multi-year process, unless they can get another CA to cross-sign their root, like LE did. I doubt other CAs will be willing to carry that level of risk given the reputation of WoSign/StartCom.
There's been some talk on mozilla.dev.security.policy about actively distrusting WoSign/StartCom-issued certificates for domains that have not been disclosed to CT as WoSign/StartCom subscribers (by baking the domain list into various browser binaries). That's probably the best option all around, though I'm not sure if it's going to happen (the report doesn't mention this).
"what does the punishment need to be to prevent others from seeing it, and thinking it's a risk worth taking?" is a better one.
For me, I think it should be permanently revoked.
The better solution would be to alert on all of their certs as being 'low trust'. A first step towards explicit trust belief, where reputations build slowly over time and can be severly damaged by bad behavior.
> We plan to distrust only newly-issued certificates to try and reduce the impact on web users [..] Our proposal is that we determine “newly issued” by examining the notBefore date [...] therefore WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.
It's more lenient than some might want, but it avoids the decision being controversial and perhaps lessens the chance that it is seriously challenged.
By far the more important element here is not that the specific corporate entity gets nuked, but that it be demonstrated to all and sundry that the CA standards have teeth. That is what will keep the bad actors from "just" doing anything to get around the problem, not psychologically-appealing vengeance.
> WoSign/StartCom could back-date certificates to get around this restriction. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.