Elektrine lite

← Feed

@agwa@follow.agwa.name

2025-12-02 13:38 UTC

Certificate authority Certum is asleep at the wheel, logging certificates to Certificate Transparency logs that are not widely trusted. Certum certificates expiring in 2027 might not work in browsers. There's really no excuse for this, as Apple and Chrome publish simple JSON files specifying exactly what logs a CA should be using!

Replies (1)

  • @agwa@follow.agwa.name 2025-12-02 16:49

    Certum, Cybertrust Japan, GlobalSign, Izenpe, NAVER, SECOM, SHECA, SSL.com, and TWCA are all issuing busted SSL certificates because instead of reading Apple and Chrome's JSON log lists which tell them exactly which Certificate Transparency logs are safe to use, they're assuming any log with "2027h1" in the name is good: https://groups.google.com/a/chromium.org/d/msgid/ct-policy/20251202114350.acbfe1173c6cad1aadfb98c7%40andrewayer.name If you got a certificate from any of these CAs in the last few days, you should test your site using SSLMate's CT Policy Analyzer: https://sslmate.com/labs/ct_policy_analyzer/

    Open ##1549353