314 karma · joined August 15, 2008
If you want to email me, use: nick (-at-) nickf (-dot-) net
Apple could fully enforce their policies and fix this in a heartbeat, but they won’t.
The root programs who have their own CAs are also cloud providers, who arguably have a legitimate need for the CA. Or in Apple's case they have their own CA, but don't issue externally. They keep CA and root program separate.
The reduction of TLS cert lifetime to a max of 398 days was an Apple policy.
If any ecosystem - such as XMPP - wishes to, they could start their own root-program, but many simply copy what Chrome or Mozilla do and then are surprised when things change.
If it's for auth, issue it yourself and don't rely on a third-party like a public CA.
If you're relying on a certificate for authentication - issue it yourself.
No-one that uses it is authenticating anything more than the other party has an internet connection and the ability, perhaps, to read. No part of the Subject DN or SAN is checked. It's just that it's 'easy' to rely on an existing trust-store rather than implement something secure using private PKI.
Some providers who 'require' public TLS certs for mTLS even specify specific products and CAs (OV, EV from specific CAs) not realising that both the CAs and the roots are going to rotate more frequently in future.
It was only ever used because other options are harder to implement.