Gentoo Archives: gentoo-dev

From: Dirkjan Ochtman <djc@g.o>
To: Gentoo Development <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] Gentoo and Root CAs
Date: Tue, 01 Jan 2013 10:52:34
Message-Id: CAKmKYaBttxTJGLoVYMN0LtNUnQvahuTTzkNrfEd8N580h8zfag@mail.gmail.com
In Reply to: Re: [gentoo-dev] Gentoo and Root CAs by Rich Freeman
1 On Tue, Jan 1, 2013 at 1:44 AM, Rich Freeman <rich0@g.o> wrote:
2 > The certificates that Gentoo distributes have at least been vouched
3 > for by somebody who is a part of our community, which is more than can
4 > be said for most of the upstream certificates.
5
6 And you think "vouched for" by some community member is better than
7 Mozilla's audit process, however limiting it may be?
8
9 Yes, the CA system is broken, but it's what we've got for now. It
10 seems obvious that including fewer CA roots in our base package is a
11 better solution than including more of them, since (a) it's pretty
12 easy for our users to install more of them, including at scale (via an
13 overlay), and (b) actual security of a CA probably goes down
14 exponentially as you move towards CA's with a lower level of trust
15 placed in them by organizations like Mozilla.
16
17 Speaking of which, say what you will about Mozilla's broken criteria
18 for root inclusion, but Mozilla has no commercial interests, pretty
19 competent security staff, and is already spending lots of staff time
20 at managing their selection of CA roots. So I think we could do worse
21 than tracking them closely (and in fact, I'd say we *are*, currently
22 doing just that -- doing worse).
23
24 IMO it would probably be good to limit our CA roots to Mozilla's
25 libnss selection by default and perhaps add a packaged selection of
26 secondary CA's (like CACert) for those who are so inclined. And if
27 Debian's process is somewhat broken, it might be best to try not to
28 rely on them. It can't be too hard, if Mozilla is already packaging
29 the certificates somehow.
30
31 Cheers,
32
33 Dirkjan

Replies

Subject Author
Re: [gentoo-dev] Gentoo and Root CAs Rich Freeman <rich0@g.o>
Re: [gentoo-dev] Gentoo and Root CAs Michael Mol <mikemol@×××××.com>
Re: [gentoo-dev] Gentoo and Root CAs "Paweł Hajdan