WoSign and letsencrypt.cn
groups.google.com
groups.google.com
> It seams that wosign has registered the domains letsencrypt.cn and letsencrypt.com.cn in 2014 after the public announce of Let's Encrypt.
And here's the whois record:
$ whois letsencrypt.cn
Domain Name: letsencrypt.cn
ROID: 20141120s10001s72911711-cn
Domain Status: clientTransferProhibited
Registrant ID: k35-n2041486_00
Registrant: 深圳市沃通电子商务服务有限公司
Registrant Contact Email: dns@wosign.com
Sponsoring Registrar: 厦门三五互联科技股份有限公司
Name Server: ns3.dns-diy.com
Name Server: ns4.dns-diy.com
Registration Time: 2014-11-20 09:57:27
Expiration Time: 2017-11-20 09:57:27
DNSSEC: unsigned
Unless they registered those domains to "reserve" them for LetsEncrypt (haha right?), this is pretty blatantly deceptive, or at least they planned to be. Then again not exactly the worst thing they've done in the world of SSL.The internet engineering community would come down like a ton of bricks if somebody registered ripe.cn and decided to impersonate RIPE. Same principle.
1. Assign DNS records to these two domains and remove them after someone exposed these domains. https://groups.google.com/d/msg/mozilla.dev.security.policy/...; https://archive.fo/MQwMK; https://archive.fo/0HQZ7
2. Send marketing e-mails that exaggerate threats of using a "foreign CA", such as Let's Encrypt: https://groups.google.com/d/msg/mozilla.dev.security.policy/... (Well, "Percy" has always been bringing it up.)
While (2) has been something too old to keep bringing up, (1) certainly undermines some of Richard Wang's claim.
Which is exactly what WoSign say they did in that same comment thread after noticing that LetsEncrypt didn't register the Chinese domain names themselves.
They also offer to transfer them to LetsEncrypt at no cost.
It is unlikely that WoSign or any CA run by WoSign will ever fully compatible with browsers in the future.
In the long run: indefinite (likely permanent) distrust by Mozilla is probably the death sentence for any CA.
(WoSign could theoretically backdate the notBefore date on new certs to make them look like existing certs, but Mozilla have said that if they catch WoSign doing this they'll distrust their root totally.)
Other browsers are taking similar measures, but I'm not sure on the details.
[0]: https://blog.mozilla.org/security/2016/10/24/distrusting-new...
[0] https://groups.google.com/forum/m/#!topic/mozilla.dev.securi...
[1] https://groups.google.com/forum/m/#!topic/mozilla.dev.securi...
---------------------------
I wish everyone can talk about this case friendly and equally.
It is very common that everyone can register any domain based on the first come and first service rule.
We know Let's Encrypt is released after the public announcement, but two day later, its .cn domain is still not registered, I think maybe it is caused by the strict registration rule in China, so I registered it for protection that not registered by Cornbug.
We don’t use those domains for any WoSign's services that we provide similar service: https://pki.click/index_En.htm (SSL Wizard, StartEncrypt)
Now, if Mozilla or Let’s Encrypt contact me officially and request to transfer the two domains to them, no any problem, we can transfer to them for FREE!
But please notice that this arrangement is for friendship, not for others ......
Best Regards,
Richard
This is a CA death penalty situation as far as I'm concerned.
As a general note, the content on the TWiT network is superb. I love the great ethics conversations that are had on TWiG (This Week in Google). I've loved listening to the "coming out of the wilderness" progression of Mary Jo Foley & Paul Thurrott with regards to Microsoft on Windows Weekly. And Security Now is my guilty educational pleasure, as its greatly expanded my knowledge of security issues and topics, which have served me well over the past few years.
Its also can be a great sleep aid.
In the new era of Software Engineering Daily and Changelog, as I see Leo Laporte as the godfather of podcasting. I disagree with a lot he has to say, but I respect him greatly and dream of meeting him one day. He is one of my heros.
And Leo: I use Emacs, and no so much Perl. I have nothing to interview for, but I can answer to your favorite question with at least half of your favorite answer, if you read this somehow!
https://twit.tv/shows/triangulation/episodes/244?autostart=f...
https://twit.tv/shows/triangulation/episodes/247?autostart=f...
The part about taking pictures of stones and his current venture at the end are less appealing to me but the discussion about the early days of Apple, and generally his view on technology is really interesting. There is a long part about AI.
tl;dr - WoSign/StartCom are no longer trusted as a CA (at least by Firefox)
Mozilla stated that they will not distrust certs issued with notBefore till December, so theoretically this cert is good for as long as it's still valid, only after that they need to worry.
Why would anyone do such an obviously bad thing and slap their company information in the whois?
After all these dramas with .cn, a wary user should reject .cn on the first sight. Too sad for Chinese/Non-technical users, as they have no choice. There's nothing can be done about the situation.
See https://certbot.eff.org/docs/using.html#renewing-certificate...
[0] https://certbot.eff.org/docs/using.html#renewing-certificate...
/path/to/letsencrypt/letsencrypt-auto -d domain.con certonly && service nginx reload
Since the domains aren't being used, we can't say what the intention was, but it's being judged as part of a pattern of behavior by Wosign.
It's a trust problem because of the pattern of this particular CA. Whether you call that a security problem or not is semantics. If not for the existing pattern of behavior, people would be a little more willing to look charitably on this as an honest mistake or trying to help, but given the history the assumption of good faith has been considerably weakened.