Skip to content

Remove CT and HPKP info from certificates page - #236

Closed
konklone wants to merge 1 commit into
masterfrom
remove-ct-hpkp
Closed

konklone wants to merge 1 commit into
masterfrom
remove-ct-hpkp

Conversation

@konklone

Copy link
Copy Markdown
Contributor

This removes the section about how to prevent CAs from issuing for your domain. This is mostly inspired by Chrome announcing that they intend to remove HPKP, but in general I also think it is better for federal agencies to understand that there's really no reliable way to prevent issuance by CAs they didn't approve. Even CAA is a best-effort approach that doesn't protect against full compromise, and I am concerned that blunt application of CAA in the federal government is likely to lead to more harm than good.

So given that, I've proposed just removing this section entirely. I could see some value in emphasizing CT, and would welcome suggestions of changes in that area, but I don't think it's worth presenting it as a way to prevent misissuance.

@konklone

Copy link
Copy Markdown
Contributor Author

@egyptiankarim egyptiankarim left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like the idea of dropping ### HTTP Public Key Pinning and nested content. Agree with the Chrome stance and with your analysis of CAA's (lack of) value in the fed.

I could see some value in emphasizing CT, and would welcome suggestions of changes in that area, but I don't think it's worth presenting it as a way to prevent misissuance.

I think the section is valuable. I'll see if I can tweak language, but I actually don't have a huge issue with the way it's currently worded. Maybe just a shift to "auditing trustworthiness" versus "preventing misissuance"?

I actually kind of appreciate the introductory text under the FAQ heading as well. Specifically:

There is no simple and 100% effective way to force all browsers to only trust certificates for your domain that have been issued from a certain CA.

I think that's a valuable statement on its own, and there's no reason to remove it really, is there?

@konklone

Copy link
Copy Markdown
Contributor Author

👍 I agree. I'll restore and tweak the CT text.

@h-m-f-t

h-m-f-t commented Oct 30, 2017

Copy link
Copy Markdown
Contributor

Agree with @egyptiankarim, I think the CT section is helpful.

I think there is value in at least mentioning HPKP, since you can more effectively dissuade its use by acknowledging it than by eliding over it.

@IanLee1521

Copy link
Copy Markdown

Agree with the above. Nothing much more for me to add. Will take another look when the tweaked version is pushed.

@konklone

Copy link
Copy Markdown
Contributor Author

Closed in favor of #239.

@konklone
konklone deleted the remove-ct-hpkp branch November 20, 2017 00:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants