|
|
|
|
|
by lexman0
3523 days ago
|
|
"Although Mozilla’s sanctions are too severe..." These guys must be joking. Trust has been lost, the roots should be permanently revoked. If anything, I think Mozilla's actions are not severe enough. How likely is it that Mozilla doesn't know the full story? There may be additional violations that have been missed. |
|
The axe Mozilla is holding over WoSign is the threat of immediate full revocation if WoSign is caught doing backdating again. Given that WoSign has been coerced into cooperating with publishing all CSRs via Certificate Transparency, and that there is likely to be a much larger group of people watching carefully for violations, I don't expect it to take very long for future backdated certificates to be caught if WoSign does try it.