Closed
Bug 1113048
Opened 11 years ago
Closed 10 years ago
https://www.electrabel.be and https://www.partenamut.be chain up to the GTE CyberTrust Global Root
Categories
(Web Compatibility :: Site Reports, defect)
Web Compatibility
Site Reports
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: info, Unassigned)
Details
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:36.0) Gecko/20100101 Firefox/36.0
Build ID: 20141217004003
Expected results:
Version: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:36.0) Gecko/20100101 Firefox/36.0
Certipost certificates are recognised in the release version (Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:34.0) Gecko/20100101 Firefox/34.0) but not in FirefoxDeveloperEdition.
| Reporter | ||
Updated•11 years ago
|
Component: Untriaged → Security
| Reporter | ||
Comment 1•11 years ago
|
||
The issue can be seen on https://www.electrabel.be/ and https://www.partenamut.be/ as well as probably many Belgian sites with a government connection.
Regression range:
http://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=38ecfc3922b8&tochange=e8df6826a571
Maybe due to:
David Keeler — bug 940506 - remove nsIRecentBadCerts and implementation r=briansmith
Component: Security → Security: PSM
Product: Firefox → Core
Comment 3•11 years ago
|
||
Looks like these sites are depending on the GTE CyberTrust Global Root, which is essentially deprecated. Bug 1088147 removed it for the second time (bug 1029561 removed it the first time, but then it was added back in bug 1046343). Kathleen, can we get in touch with the CA these sites are using so they can help them send the right intermediates?
Flags: needinfo?(kwilson)
Comment 4•11 years ago
|
||
Steven, These Certipost folks are still chaining up to the GTE CyberTrust Gobal Root, which is being removed in Firefox 36.
Flags: needinfo?(kwilson)
| Reporter | ||
Comment 5•11 years ago
|
||
Thanks for the info.
I sent a message explaining the issue to both Bpost (the Belgian postal service behind Certipost) and the @certipost.be email address provided in their certificate. Hopefully they will quickly get in touch with their customers to sort this out.
Updated•10 years ago
|
Component: Security: PSM → Desktop
OS: Mac OS X → All
Product: Core → Tech Evangelism
Hardware: x86 → All
Version: 36 Branch → Trunk
Comment 6•10 years ago
|
||
David, is there any point at which we're going to re-introduce them a second time if not enough servers have been updated? :-(
Flags: needinfo?(dkeeler)
Comment 7•10 years ago
|
||
(In reply to :Gijs Kruitbosch from comment #6)
> David, is there any point at which we're going to re-introduce them a second
> time if not enough servers have been updated? :-(
We would rather avoid doing that. Let's try to get in touch with these sites to see if we can help them update their configuration.
Steven, have you had any success reaching out to your customers that are still using deprecated intermediate certificates?
Flags: needinfo?(dkeeler) → needinfo?(steve.medin)
Comment 8•10 years ago
|
||
Certipost were aware of the need to replace GTE-based subordinates in the distant past, we first broadcasted our 1024-bit deprecation strategy to customers in early 2011. Organizational changes led to the action lagging to this point. Subordinate CAs for Certipost under our mainstream Baltimore CyberTrust Global Root were created in October 2013. Our operations team is finalizing the updated name constraint content of a new set of subordinates to be issued in the near future and distributed. These will be chain-pluggable substitutes for the existing CAs under the GTE root that reuse the previous PKCS#10s to expedite field replacement and avoid end entity re-enrollment.
A similar story carries across each lagging customer, as we've been banging the drum for years. It is often a quantity of certificates versus current staffing level to replace the certificates obstacle caused by downsizing from heyday PKI team sizes.
Flags: needinfo?(steve.medin)
Comment 9•10 years ago
|
||
Both of these sites now chain up to different roots.
Status: UNCONFIRMED → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
Summary: Certipost certificate issuer is not known → https://www.electrabel.be and https://www.partenamut.be chain up to the GTE CyberTrust Global Root
| Assignee | ||
Updated•6 years ago
|
Product: Tech Evangelism → Web Compatibility
You need to log in
before you can comment on or make changes to this bug.
Description
•