Issue metadata
Sign in to add a comment
|
StartCom Root CA and WoSign is still considered 'Trusted'
Reported by
rpark...@gmail.com,
Nov 4 2016
|
||||||||||||||||||||
Issue descriptionChrome Version : 56.0.2909.0 (Developer Build) (64-bit) URLs (if applicable) : https://www.rpark.co/2016/11/04/startssl-wosign-ca-not-trust-anymore/, http://www.percya.com/2016/08/chinese-ca-wosign-faces-revocation.html, https://pierrekim.github.io/blog/2016-02-16-why-i-stopped-using-startssl-because-of-qihoo-360.html, https://freevps.us/thread-19191.html, https://groups.google.com/forum/m/#!msg/mozilla.dev.security.policy/BV5XyFJLnQM/_DwiB1PDGQAJ Other browsers tested: Add OK or FAIL, along with the version, after other browsers where you have tested this issue: Safari: N/A Firefox: OK, https://groups.google.com/forum/m/#!msg/mozilla.dev.security.policy/BV5XyFJLnQM/_DwiB1PDGQAJ IE: N/A What steps will reproduce the problem? (1) Go to www.startcom.com, go to www.wosign.com (2) Certificate Authorities are clearly still trusted. (3) What is the expected result? WoSign and StartCom's Root CA Trust should be Revoked due to security issues. Please read the links for more information. What happens instead? The two Root CA's are still trusted. Please provide any additional information below. Attach a screenshot if possible. |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by rsleevi@chromium.org
, Nov 8 2016Status: Duplicate (was: Unconfirmed)