Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248132

Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still included in Bullseye?

From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still included in Bullseye?
Date 2022-05-12 17:20 +0200
Message-ID <EmiLD-f09a-1@gated-at.bofh.it> (permalink)
References <Emish-eZM8-1@gated-at.bofh.it> <EmiBX-f05O-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Thu, May 12, 2022 at 06:06:41PM +0300, IL Ka wrote:
> Hi.
> 
> OSes usually include all CA certificates (even expired). Windows also does
> it (I have CA expired in 1999 in win10).
> 
> User should have the ability to distinguish between invalid signatures and
> old/expired signatures.
> While the latter is an expected situation, the former is definitely fraud.

This makes sense. OpenSSL is not only for stuff travelling in space,
but also travelling in time (typically travelling from the past to
the future; the other direction isn't yet quite common).

Think S/MIME mail sleeping in a mailbox for a couple of years. How
are you supposed to check an old mail's signature if you throw away
your old certificates?

Of course, you're using PGP (best in its gpg implementation), not
S/MIME. But there, you face a similar problem.

Keep your old keys around for as long as you keep your old encrypted
or signed material around.

Cheers
-- 
t

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

ca-certificates: DST_Root_CA_X3.crt expired, so why is it still  included in Bullseye? Harald Dunkel <harald.dunkel@aixigo.com> - 2022-05-12 17:00 +0200
  Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still  included in Bullseye? IL Ka <kazakevichilya@gmail.com> - 2022-05-12 17:10 +0200
    Re: ca-certificates: DST_Root_CA_X3.crt expired, so why is it still  included in Bullseye? <tomas@tuxteam.de> - 2022-05-12 17:20 +0200

csiph-web