csosto-pk / tls-suppress-intermediates

Suppress intermediate certificates in TLS
Other
0 stars 0 forks source link

CCADB's ICA list accuracy #14

Open csosto-pk opened 2 years ago

csosto-pk commented 2 years ago

If a 3rd party repo was hosting the ICA list for WebPKI, then we could limit outages because

We should think about this more.

csosto-pk commented 2 years ago

Reach out to CCADB https://groups.google.com/a/mozilla.org/g/dev-security-policy

csosto-pk commented 2 years ago

CCADB already hosts them here https://ccadb-public.secure.force.com/mozilla/MozillaIntermediateCertsCSVReport and we confirmed these are the same FiloSottile pulls from. So, there is a third-party that hosts them already.

Now we need to study how good this list is; meaning if the ICAs start getting used before they show up in the list.