Re: Increasing number of Errors found in crt.sh

2018-10-02 Thread Rob Stradling via dev-security-policy
y-policy on behalf of Adriano Santoni via dev-security-policy Sent: Monday, October 01, 2018 10:09 PM To: Rob Stradling; Doug Beattie Cc: mozilla-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh I also agree. As I said before, that's a non-trusted certificate

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
e filtered report once it returns to life. Doug *From:*Wayne Thayer *Sent:* Monday, October 1, 2018 2:58 PM *To:* Doug Beattie *Cc:* mozilla-dev-security-policy *Subject:* Re: Increasing number of Errors found in crt.sh Doug, Responding to your original question, I look at crt.sh and other dat

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
://misissued.com and use that as a better, more filtered report once it returns to life. Doug From: Wayne Thayer Sent: Monday, October 1, 2018 2:58 PM To: Doug Beattie Cc: mozilla-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh Doug, Responding to

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Wayne Thayer via dev-security-policy
gt; Regards > > > > From: dev-security-policy > on behalf of Adriano Santoni via dev-security-policy < > dev-security-policy@lists.mozilla.org> > > Sent: Monday, October 01, 2018 10:09 PM > > To: Rob Stradling; Doug Beatt

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
la-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh I also agree. As I said before, that's a non-trusted certificate. It was issued by a test CA that does /not/ chain to a public root. Il 01/10/2018 16:04, Rob Stradling ha scritto: On 01/10/2018 15:02, Doug Beat

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
> -Original Message- > From: dev-security-policy mailto:dev-security-policy-boun...@lists.mozilla.org>> On > Behalf Of Adriano Santoni via dev-security-policy > Sent: Monday, October 1, 2018 9:49 AM > To: dev-security-policy@lists.mozilla.org

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Inigo Barreira via dev-security-policy
; Doug Beattie Cc: mozilla-dev-security-policy Subject: Re: Increasing number of Errors found in crt.sh I also agree. As I said before, that's a non-trusted certificate. It was issued by a test CA that does /not/ chain to a public root. Il 01/10/2018 16:04, Rob Stradling ha scritto: > On 01

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Adriano Santoni via dev-security-policy
riginal Message- From: dev-security-policy On Behalf Of Adriano Santoni via dev-security-policy Sent: Monday, October 1, 2018 9:49 AM To: dev-security-policy@lists.mozilla.org Subject: Re: Increasing number of Errors found in crt.sh Thank you Rob! If I am not mistaken, it seems to me that w

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Alex Gaynor via dev-security-policy
ually, some non-publicly-trusted roots are accepted by some of the > logs that crt.sh monitors. > > > Doug > > > > -Original Message- > > From: dev-security-policy > On > > Behalf Of Adriano Santoni via dev-security-policy > > Sent: Monday, October 1, 201

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
Increasing number of Errors found in crt.sh Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test CA). Il 01/10/2018 15:43, Rob Stradling via dev-security-policy ha scritto: On 01/10/2018 1

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
security-policy Sent: Monday, October 1, 2018 9:49 AM To: dev-security-policy@lists.mozilla.org Subject: Re: Increasing number of Errors found in crt.sh Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was i

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
On 01/10/2018 14:48, Adriano Santoni via dev-security-policy wrote: Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test CA). For certs issued (and logged) within the last 1 week, yes, tha

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Adriano Santoni via dev-security-policy
Thank you Rob! If I am not mistaken, it seems to me that we have just 1 certificate in that list, and it's a non-trusted certificate (it was issued by a test CA). Il 01/10/2018 15:43, Rob Stradling via dev-security-policy ha scritto: On 01/10/2018 14:38, Adriano Santoni via dev-security-poli

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Rob Stradling via dev-security-policy
On 01/10/2018 14:38, Adriano Santoni via dev-security-policy wrote: Is it possible to filter the list https://crt.sh/?cablint=issues based on the issuing CA ? Yes. First, visit this page: https://crt.sh/?cablint=1+week Next, click on the link in the "Issuer CN, OU or O" column that correspon

Re: Increasing number of Errors found in crt.sh

2018-10-01 Thread Adriano Santoni via dev-security-policy
Is it possible to filter the list https://crt.sh/?cablint=issues based on the issuing CA ? Il 01/10/2018 15:26, Doug Beattie via dev-security-policy ha scritto: Hi Wayne and all, I've been noticing an increasing number of CA errors, https://crt.sh/?cablint=issues Is anyone monitoring thi

RE: Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
Errors found in crt.sh Hi Wayne and all, I've been noticing an increasing number of CA errors, https://crt.sh/?cablint=issues Is anyone monitoring this list and asking for misissuance reports for those that are not compliant? There are 15 different errors and around 300 individual e

Increasing number of Errors found in crt.sh

2018-10-01 Thread Doug Beattie via dev-security-policy
Hi Wayne and all, I've been noticing an increasing number of CA errors, https://crt.sh/?cablint=issues Is anyone monitoring this list and asking for misissuance reports for those that are not compliant? There are 15 different errors and around 300 individual errors (excluding the SHA-1 "false