Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 668932 - app-misc/ca-certificates: Consider removing Symantec certs
Summary: app-misc/ca-certificates: Consider removing Symantec certs
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-10-18 09:05 UTC by Hanno Böck
Modified: 2020-06-02 17:14 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2018-10-18 09:05:27 UTC
I guess everyone's aware that the Symantec certs are being distrusted and by now it should be safe to remove them, as major browsers start showing warnings. (I saw we had a previous bug on this in #613714, but the changes have been reverted.)

This will eventually happen automatically, as we use Debian ca-certificates as upstream which takes the data from nss which eventually will remove it. But we may want to do things faster than that. (I reported this to Debian as well).

It also needs some careful checking, as there are various brands (Thawte, Geotrust, Verisign) that are owned by Symantec, yet there are also roots from that brands that got sold to other companies and are not part of the distrust.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-10-18 09:17:16 UTC
Won't happen before distrusted in Mozilla and Chrome but both vendors stepped away from their timeline: https://blog.mozilla.org/security/2018/10/10/delaying-further-symantec-tls-certificate-distrust/ and even Google pushed back from initial plan to distrust Symantec in v70 for same reason.
Comment 2 Hanno Böck gentoo-dev 2020-06-02 09:41:41 UTC
Debian's just released ca-certificates package 20200601 removes the old symantec certs, so this should be done by the next bump.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2020-06-02 10:12:51 UTC
It's not yet on the mirrors.
Comment 4 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2020-06-02 17:14:37 UTC
Completed now in ca-certificates-20200601.3.53