Re: Increasing number of Errors found in crt.sh

2018-10-02 Thread Rob Stradling via dev-security-policy
of Adriano Santoni via dev-security-policy Sent: Monday, October 01, 2018 10:09 PM To: Rob Stradling; Doug Beattie Cc: mozilla-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh I also agree. As I said before, that's a non-trusted certificate. It was issued by a test

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
report once it returns to life. Doug *From:*Wayne Thayer *Sent:* Monday, October 1, 2018 2:58 PM *To:* Doug Beattie *Cc:* mozilla-dev-security-policy *Subject:* Re: Increasing number of Errors found in crt.sh Doug, Responding to your original question, I look at crt.sh and other data sources

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
://misissued.com and use that as a better, more filtered report once it returns to life. Doug From: Wayne Thayer Sent: Monday, October 1, 2018 2:58 PM To: Doug Beattie Cc: mozilla-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh Doug, Responding

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Wayne Thayer via dev-security-policy
> > From: dev-security-policy > on behalf of Adriano Santoni via dev-security-policy < > dev-security-policy@lists.mozilla.org> > > Sent: Monday, October 01, 2018 10:09 PM > > To: Rob Stradling; Doug Beattie > > Cc: mozilla-dev-s

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
-policy Subject: Re: Increasing number of Errors found in crt.sh I also agree. As I said before, that's a non-trusted certificate. It was issued by a test CA that does /not/ chain to a public root. Il 01/10/2018 16:04, Rob Stradling ha scritto: On 01/10/2018 15:02, Doug Beattie via dev-security

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
--- > From: dev-security-policy mailto:dev-security-policy-boun...@lists.mozilla.org>> On > Behalf Of Adriano Santoni via dev-security-policy > Sent: Monday, October 1, 2018 9:49 AM > To: dev-security-policy@lists.mozilla.org <mailto:dev-security-p

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Inigo Barreira via dev-security-policy
; Doug Beattie Cc: mozilla-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh I also agree. As I said before, that's a non-trusted certificate. It was issued by a test CA that does /not/ chain to a public root. Il 01/10/2018 16:04, Rob Stradling ha scritto: > On 01/10/2

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Adriano Santoni via dev-security-policy
- From: dev-security-policy On Behalf Of Adriano Santoni via dev-security-policy Sent: Monday, October 1, 2018 9:49 AM To: dev-security-policy@lists.mozilla.org Subject: Re: Increasing number of Errors found in crt.sh Thank you Rob! If I am not mistaken, it seems to me that we have just 1 c

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Alex Gaynor via dev-security-policy
ed roots are accepted by some of the > logs that crt.sh monitors. > > > Doug > > > > -Original Message- > > From: dev-security-policy > On > > Behalf Of Adriano Santoni via dev-security-policy > > Sent: Monday, October 1, 2018 9:49 AM > > To: dev-secur

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
ing number of Errors found in crt.sh Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test CA). Il 01/10/2018 15:43, Rob Stradling via dev-security-policy ha scritto: On 01/10/2018 14:38, Adriano S

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
olicy Sent: Monday, October 1, 2018 9:49 AM To: dev-security-policy@lists.mozilla.org Subject: Re: Increasing number of Errors found in crt.sh Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
On 01/10/2018 14:48, Adriano Santoni via dev-security-policy wrote: Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test CA). For certs issued (and logged) within the last 1 week, yes,

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Adriano Santoni via dev-security-policy
Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test CA). Il 01/10/2018 15:43, Rob Stradling via dev-security-policy ha scritto: On 01/10/2018 14:38, Adriano Santoni via

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
On 01/10/2018 14:38, Adriano Santoni via dev-security-policy wrote: Is it possible to filter the list https://crt.sh/?cablint=issues based on the issuing CA ? Yes. First, visit this page: https://crt.sh/?cablint=1+week Next, click on the link in the "Issuer CN, OU or O" column that

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Adriano Santoni via dev-security-policy
Is it possible to filter the list https://crt.sh/?cablint=issues based on the issuing CA ? Il 01/10/2018 15:26, Doug Beattie via dev-security-policy ha scritto: Hi Wayne and all, I've been noticing an increasing number of CA errors, https://crt.sh/?cablint=issues Is anyone monitoring

Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
Hi Wayne and all, I've been noticing an increasing number of CA errors, https://crt.sh/?cablint=issues Is anyone monitoring this list and asking for misissuance reports for those that are not compliant? There are 15 different errors and around 300 individual errors (excluding the SHA-1