Termination of StartCom business
startcomca.com
startcomca.com
I found that addendum quite strange. Such thing should be opt-in, in my opinion.
https://nakedsecurity.sophos.com/2013/01/08/the-turktrust-ss...
> Eddy Nigg (StartCom)
> Comment 11 • 7 years ago
> According to http://www.mozilla.org/projects/security/certs/policy/ and https://wiki.mozilla.org/CA:Information_checklist apparently fails to comply to the audit requirements amongst other things at the moment. Should a valid audit statement be published and confirmed by an authorized auditor, I guess Mozilla could consider a discussion to include this CA.
I always hated their interface but as a broke high school student I couldn’t afford to have a paid certificate. Thankfully we have Let’s Encrypt now
> Hi,
>
> Sure, we will record your user ID and your details won't be transferred to other CA, as the alternative CA option is for those who need it.
>
> Best regards,
> StartCom Certification
> AuthorityThis is an automatically generated email, please do not reply.
Dear customer,
As you are surely aware, the browser makers distrusted StartCom around a year ago and therefore all the end entity certificates newly issued by StartCom are not trusted by default in browsers.
The browsers imposed some conditions in order for the certificates to be re-accepted. While StartCom believes that these conditions have been met, it appears there are still certain difficulties forthcoming. Considering this situation, the owners of StartCom have decided to terminate the company as a Certification Authority as mentioned in Startcom´s website.
StartCom will stop issuing new certificates starting from January 1st, 2018 and will provide only CRL and OCSP services for two more years.
StartCom would like to thank you for your support during this difficult time.
StartCom is contacting some other CAs to provide you with the certificates needed. In case you don´t want us to provide you an alternative, please, contact us at certmaster@startcomca.com
Please let us know if you need any further assistance with the transition process. We deeply apologize for any inconveniences that this may cause.
Best regards,
StartCom Certification Authority
The full raw email: https://lukeshu.com/dump/startcom-email.txt
In HTML4/XHTML1, the <meta http-equiv> isn't meant to be interpreted by the user agent; the HTTP server is supposed to parse it and set the the HTTP header accordingly.
Of course, the people writing the (X)HTML probably have a better idea of what encoding they're using than the people configuring the HTTP server, so it's common for user agents to allow <meta http-equiv> to override the actual header, as it allows more things to work "correctly" for users. But, strictly speaking, that is non-conforming.
In (X)HTML5, that practice was codified, and the <meta http-equiv> tag is given preference over the actual headers (for a whitelist of allowed headers).
So, which interpretation is "correct" depends on if it is HTML4/XHTML1 or (X)HTML5.
Now, the MIME type of the email body said "text/html" which can be anything, and the body used the HTML5 doctype, but specified the XHTML1 xmlns. I'm honestly not sure which interpretation is correct in that case.
Some previous discussion is here:
"gail.com" is probably one of the most valuable typo squats, but it's also someone's name.
Yes, I know that changing website templates requires effort, and that's effort that they no longer have any reason to spend.
"Hi,
Sure, we will record your user ID and your details won't be transferred to other CA, as the alternative CA option is for those who need it.
Startcom certification Authority"