Chrome canary (66) blocks symantec issued SSL certificates
twitter.com
twitter.com
https://security.googleblog.com/2017/09/chromes-plan-to-dist...
After Google published that post, Symantec responded with their own open letter objecting to Google here:
https://www.symantec.com/connect/blogs/symantec-backs-its-ca
However they subsequently relented, and decided to sell their PKI business to Digicert rather than rebuild it as would be necessary to regain browser trust.
I run Linux and unfortunately Google hasn't seen fit to grace us with access to Canary on this platform.
EDIT: I'm an idiot, it didn't occur to me that Symantec didn't sign their own cert. But they don't, it's from DigiCert. Can anyone link to a site that uses Symantec certs?
Console throws up this warning about M70 though.
> The SSL certificate used to load resources from https://static.ctctcdn.com will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information.
Says Symantec sold their cert business to DigiCert
So could it be a cert that was issued as Symantec and just now shows as DigiCert and would still give you the error?
https://download-chromium.appspot.com/?platform=Linux_x64&ty...
I deeply appreciate that's not "Chrome," nor Canary, but wanted to offer it in case you weren't previously aware
But it's easy in a short browsing session for your User Agent to connect to hundreds of machines over TLS. Manually verifying them all is not feasible. And verify against what? A webpage? How is that validated.
TLS and X.509 certs have their flaws, but ssh style trust is not the solution.
The problem is: if your browser adds a CA to it's trust root, it can issue (and thus your browser trusts) any site on the internet.
I would rather that if I visit https://www.police.uk then the certificate is issued by a CA that specifically allowed to issue .uk domain certs.
Currently my system trusts "Belguim Root CA2" and "Amazon Root CA 1". Should they be able to sign certs for the .ca or .edu domains?
Do I trust Amazon enough to not issue certs for their competitors?