#808568 ca-certificates: show certificates subjects

#808568#5
Date:
2015-12-21 02:08:05 UTC
From:
To:
Hi.

Right now, the selection dialog when reconfiguring
the enabled certificates shows the pathnames of their
files, which in turn are apparently based on the OU
filed.
This seems in many cases pretty unclear, e.g.
"mozilla/ePKI_Root_Certification_Authority.crt"

It would help IMHO, if additionally the whole subject DN
would be printed, e.g.
"/C=TW/O=Chunghwa Telecom Co., Ltd./OU=ePKI Root Certification Authority"

Given that Mozilla includes for money basically any
CA nowadays, even such which are inherently untrustworthy
it seems especially helpful, if the C filed would
be shown, so that people who don't want to make themselves
unnecessarily victims of totalitarian countries, can
more easily sort out CAs from there.

Thanks,
Chris.

#808568#10
Date:
2015-12-21 09:23:46 UTC
From:
To:
Such polarizing comments are not welcome and do not serve to improve
Debian. I'm closing the bug now. Please refrain from posting new bugs as
long as you intend to include statements that accuse colleague developers
of corruption.

We will welcome any factual bug reports that do not seek to spread FUD or
polarize as this is very much off topic for the Debian BTS.


Cheers,
Thijs

#808568#15
Date:
2015-12-22 00:15:23 UTC
From:
To:
Control: tags -1 + wontfix
I'm afraid when factual issues are considered polarising.
Well serving examples for such CA's should include e.g. CNNIC or
TURKTRUST (yeah, of course, it was an "accident" that they created
forged google.com certs and placed them in the wild o.O)
Uhm, if you read closely, I haven't accused anyone of corruption,
neither specific developers, not even Mozilla, even though what the
later does is morally probably not that much better - but everyone has
to decide this for himself.
What I wrote was, that "any CA is included for money", and AFAIU, this
is the actual way: a CA needs to get some organisation having an audit
done, which in turn it pays for.
The worth of the audits in turn, was e.g. shown in the DigiNotar or
again TURKTRUST cases.
CAs in turn typically earn their money (and lots more) back by selling
certificates.


So I'm afraid you consider my comments polarising, but it wasn't me who
made the system as it is.
Further, I would enjoy if you wouldn't ready any statements of mine
between the lines which there aren't written. Maybe words weren't clear
enough as I'm no native English speaker, but before accusing me of
allegedly accusing some "colleague developers" of corruption, it would
have been perhaps not so inappropriate to ask whether this is meant or
not.
As for the enhancement request itself, it may be acceptable for you to
have CAs included which, by accident or not, release forged
certificates - other Debian users may however not desire this.

I read the closing of the bug, based on my motivation text why it makes
sense for improving the listing of ca-certificates debconf selection
dialogue, that such change is not desired.
Therefore, I think, the bug should additionally be marked wontfix,
please correct me if wrong.


Cheers,
Chris.

#808568#22
Date:
2015-12-22 07:36:21 UTC
From:
To:
"Given that Mozilla includes for money basically any
CA nowadays, even such which are inherently untrustworthy"

As you've clarified, apparently your opinion is that audits alone are not
reliable to determine worthiness of inclusion and you wish to see full
certificate subjects to better make your own choice of which CA's to
trust. I personally doubt whether the C= field is a reliable indicator of
that, but that is up to you.

By not formulating it this way, but instead choosing to use the statement
above 'will do (basically) anything for money', you choose to put focus
explicitly on the fact that it costs money and highly suggest a moral
judgment of their operation. It is really not a matter of language
difference that you choose to play the money card. It doesn't help to add
the claim that some CA's are 'inherently' untrustworthy in the same
sentence, which further reinforces the connection between accepting money
and doing something morally rejectable.

It's clear to me that you're strongly opinionated about the workings of
the CA system; your concerns also surface again in your followup. However,
I believe the BTS is not the right platform for that.

As for your request, I will reopen it and we can consider the
possibilities of it. I do hope that in the future you can show some
restraint in your approach.


Cheers,
Thijs