Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #248132
| From | <tomas@tuxteam.de> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still included in Bullseye? |
| Date | 2022-05-12 17:20 +0200 |
| Message-ID | <EmiLD-f09a-1@gated-at.bofh.it> (permalink) |
| References | <Emish-eZM8-1@gated-at.bofh.it> <EmiBX-f05O-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On Thu, May 12, 2022 at 06:06:41PM +0300, IL Ka wrote: > Hi. > > OSes usually include all CA certificates (even expired). Windows also does > it (I have CA expired in 1999 in win10). > > User should have the ability to distinguish between invalid signatures and > old/expired signatures. > While the latter is an expected situation, the former is definitely fraud. This makes sense. OpenSSL is not only for stuff travelling in space, but also travelling in time (typically travelling from the past to the future; the other direction isn't yet quite common). Think S/MIME mail sleeping in a mailbox for a couple of years. How are you supposed to check an old mail's signature if you throw away your old certificates? Of course, you're using PGP (best in its gpg implementation), not S/MIME. But there, you face a similar problem. Keep your old keys around for as long as you keep your old encrypted or signed material around. Cheers -- t
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
ca-certificates: DST_Root_CA_X3.crt expired, so why is it still included in Bullseye? Harald Dunkel <harald.dunkel@aixigo.com> - 2022-05-12 17:00 +0200
Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still included in Bullseye? IL Ka <kazakevichilya@gmail.com> - 2022-05-12 17:10 +0200
Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still included in Bullseye? <tomas@tuxteam.de> - 2022-05-12 17:20 +0200
csiph-web