[cabfpub] LV Certificates

Peter Bowen pzb at amzn.com
Fri Dec 18 15:42:27 MST 2015


The proposers make the claim "anywhere from 2-7% of global user agents are unable to use HTTPS sites utilizing SHA-2 signature algorithms”.  It would be helpful to have more concrete data.  Would CloudFlare and Facebook be willing to share data on the top user agents (including versions and OS platform) which would be receiving these LV certificates, if they are approved?  Both have publicly stated they are using the type of algorithm proposed in the ballot, so such data should not be hard to get.

Thanks,
Peter

> On Dec 18, 2015, at 2:36 PM, Jeremy Rowley <jeremy.rowley at digicert.com> wrote:
> 
> For now I’m presenting it on behalf of non-members of the Forum, but I will likely sponsor if I get the necessary internal approvals.
>  
> From: Ryan Sleevi [mailto:sleevi at google.com] 
> Sent: Friday, December 18, 2015 3:24 PM
> To: Jeremy Rowley
> Cc: CABFPub
> Subject: Re: [cabfpub] LV Certificates
>  
> Jeremy,
>  
> Is this something DigiCert is endorsing, or are you merely presenting it on behalf of non-members of the Forum in the effort to find sponsors and endorsers?
>  
> On Fri, Dec 18, 2015 at 2:21 PM, Jeremy Rowley <jeremy.rowley at digicert.com> wrote:
> Hi everyone,
>  
> Attached is a proposal from Cloudflare and Facebook creating LV certificates in the baseline requirements.  This is a draft ballot for review that will, of course, change based on the debate in the forum. Although CAs will stop issuing SHA-1 on 2016/1/1, there isn’t any reason these changes couldn’t go into effect in early January (assuming a passing vote).
>  
> If adopted, this ballot would permit continued use of SHA1 certificates past the deprecation deadline (to support older devices) but give newer browsers an easy way to reject SHA1 for users.  The ballot also increases the resiliency of SHA1 certs against attacks by requiring higher entropy serial numbers.
>  
> I look forward to your comments.
>  
> Thanks,
> Jeremy


More information about the Public mailing list