Trusted End Node Security
spi.dod.mil
spi.dod.mil
Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.
I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust
They do it precisely because they cannot trust any other CAs. You cannot trust any CAs — and yet you do. Go into your browser: odds are you have CAs controlled by the Russian, Chinese & Turkish governments. You're not just trusting those CAs to issue certificates for .cn, .ru or .tr: you're trusting them for every TLD in the world, to include .com, .gov & .mil. Yes, if you're using XPKI (the standard PKI basically everything on the Internet uses), you're trusting that the Chinese government will never man-in-the-middle your sessions with the IRS. The DoD (rather wisely) chooses to trust only itself to certify itself.
My own opinion is that what we should have done was adopt a system which leveraged DNS to delegate trust (note that this is what Let's Encrypt does), and that we should have rooted DNS in a multinational board: if the U.S., China, Russia, Iran, the United Kingdom, the Ukraine, France & Mexico all agree on something, it's really very likely to be true.
We should also have leveraged IP assignments. Imagine if when you talked to a system it produced proof that it really is allowed to have its IP address and that it really is allowed to speak for a particular domain. That's really what people want, not some sort of nebulous tie to a real-world identity. What we care about is that facebook.com is facebook.com, not that it's Facebook, Inc., headquartered in Menlo Park.
Isn't it a double edge sword though with what they chose to do instead? By the DoD using their own CA people accessing their sites externally or on non-DoD devices cannot reliably know if they're being ease dropped on either. It has it's benefits for DoD employees using DoD devices but anyone outside the DoD needs to roll the dice or first request the CA root cert from a DoD employee?
/edit. That was a very long time ago though so I'm not sure if they're even using that same screen sharing site anymore or if they've since changed it to use a public CA root cert.
Public companies don't typically have "our CA getting hacked by a foreign power in a war affecting all our traffic" as a part of their threat model, which is why public companies can use public CAs without worry.
They are in a kind of unique position.
https://iase.disa.mil/pki-pke/Pages/tools.aspx
*under Trust Store
I see that it is read-only media so I suppose that helps, but in the end its still only as secure as the machine that you run it from.
Uh-oh. They argue that this is not an issue since the drive is read only, preventing any persistence of malware between sessions. However, this still means that there are known and fixable holes in the system which are exposed in using TENS; just because the malware goes away when you reboot, doesn't make it ok to allow malware in in the first place.
Also, what about literally any hardware security threats, like physical keyloggers or any evil low level software (bios, eufi, etc)
It's not the worst option out there, but it's far from a "general purpose" Linux LiveCD.
The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported.
Error code: SEC_ERROR_UNKNOWN_ISSUER
----
Neat