After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 772897 - Consider switching from StartCom to a different CA
Consider switching from StartCom to a different CA
Status: RESOLVED FIXED
Product: sysadmin
Classification: Infrastructure
Component: Certificates
unspecified
Other All
: Normal minor
: ---
Assigned To: GNOME Sysadmins
GNOME Sysadmins
Depends on:
Blocks: 774465
 
 
Reported: 2016-10-13 22:10 UTC by userwithuid
Modified: 2016-11-15 21:21 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description userwithuid 2016-10-13 22:10:25 UTC
As you might have heard, recently, there has been quite the discussion about the trustworthiness and future of WoSign, who (now not so secretly any more) owns StartCom: https://wiki.mozilla.org/CA:WoSign_Issues

There has been talk (mozilla/google) and a little action (apple) about distrusting WoSign certificates in some form, but I doubt they will block current certs from StartCom - too many sites use them currently.

Nevertheless, if it was not already planned, I want to suggest *.gnome.org switch to another certificate provider. The practical reason is that the current cert expires 2017-03 and who knows if the renewed one will be trusted everywhere? My personal reason is that I want this and other sites not to support a -imho- bad CA and make it possible to eventually distrust everything WoSign related without having too much stuff fail, but whatever. :-P One step at a time: https://kernel.org/gandinet-tls-certificates.html
Comment 1 christensen.fin 2016-11-04 09:18:45 UTC
I was unable to install any gnome shell extension as StartCom got untrusted on my system (the download of the extension failed silently in the gnome-shell). I readded the StartCom certificates and extension installation is working again. You should consider moving to a new CA in the near future.
Comment 2 Andrea Veri 2016-11-04 09:44:37 UTC
We're on it. Thanks!
Comment 3 Andrea Veri 2016-11-15 21:21:24 UTC
The migration is now COMPLETED! Thanks!