- Package:
- ca-certificates
- Source:
- ca-certificates
- Submitter:
- Christoph Anton Mitterer
- Date:
- 2015-12-22 07:45:09 UTC
- Severity:
- wishlist
Hi. Right now, the selection dialog when reconfiguring the enabled certificates shows the pathnames of their files, which in turn are apparently based on the OU filed. This seems in many cases pretty unclear, e.g. "mozilla/ePKI_Root_Certification_Authority.crt" It would help IMHO, if additionally the whole subject DN would be printed, e.g. "/C=TW/O=Chunghwa Telecom Co., Ltd./OU=ePKI Root Certification Authority" Given that Mozilla includes for money basically any CA nowadays, even such which are inherently untrustworthy it seems especially helpful, if the C filed would be shown, so that people who don't want to make themselves unnecessarily victims of totalitarian countries, can more easily sort out CAs from there. Thanks, Chris.
Such polarizing comments are not welcome and do not serve to improve Debian. I'm closing the bug now. Please refrain from posting new bugs as long as you intend to include statements that accuse colleague developers of corruption. We will welcome any factual bug reports that do not seek to spread FUD or polarize as this is very much off topic for the Debian BTS. Cheers, Thijs
Control: tags -1 + wontfix I'm afraid when factual issues are considered polarising. Well serving examples for such CA's should include e.g. CNNIC or TURKTRUST (yeah, of course, it was an "accident" that they created forged google.com certs and placed them in the wild o.O) Uhm, if you read closely, I haven't accused anyone of corruption, neither specific developers, not even Mozilla, even though what the later does is morally probably not that much better - but everyone has to decide this for himself. What I wrote was, that "any CA is included for money", and AFAIU, this is the actual way: a CA needs to get some organisation having an audit done, which in turn it pays for. The worth of the audits in turn, was e.g. shown in the DigiNotar or again TURKTRUST cases. CAs in turn typically earn their money (and lots more) back by selling certificates. So I'm afraid you consider my comments polarising, but it wasn't me who made the system as it is. Further, I would enjoy if you wouldn't ready any statements of mine between the lines which there aren't written. Maybe words weren't clear enough as I'm no native English speaker, but before accusing me of allegedly accusing some "colleague developers" of corruption, it would have been perhaps not so inappropriate to ask whether this is meant or not. As for the enhancement request itself, it may be acceptable for you to have CAs included which, by accident or not, release forged certificates - other Debian users may however not desire this. I read the closing of the bug, based on my motivation text why it makes sense for improving the listing of ca-certificates debconf selection dialogue, that such change is not desired. Therefore, I think, the bug should additionally be marked wontfix, please correct me if wrong. Cheers, Chris.
"Given that Mozilla includes for money basically any CA nowadays, even such which are inherently untrustworthy" As you've clarified, apparently your opinion is that audits alone are not reliable to determine worthiness of inclusion and you wish to see full certificate subjects to better make your own choice of which CA's to trust. I personally doubt whether the C= field is a reliable indicator of that, but that is up to you. By not formulating it this way, but instead choosing to use the statement above 'will do (basically) anything for money', you choose to put focus explicitly on the fact that it costs money and highly suggest a moral judgment of their operation. It is really not a matter of language difference that you choose to play the money card. It doesn't help to add the claim that some CA's are 'inherently' untrustworthy in the same sentence, which further reinforces the connection between accepting money and doing something morally rejectable. It's clear to me that you're strongly opinionated about the workings of the CA system; your concerns also surface again in your followup. However, I believe the BTS is not the right platform for that. As for your request, I will reopen it and we can consider the possibilities of it. I do hope that in the future you can show some restraint in your approach. Cheers, Thijs