[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #4583 [Tor Bridge]: Obfuscate the default certificate validity times (was: Implement certificate start time fuzzing (part of proposal 179))
#4583: Obfuscate the default certificate validity times
------------------------+---------------------------------------------------
Reporter: asn | Owner:
Type: defect | Status: needs_review
Priority: normal | Milestone:
Component: Tor Bridge | Version:
Keywords: | Parent: #3972
Points: | Actualpoints:
------------------------+---------------------------------------------------
Comment(by asn):
Replying to [comment:2 nickm]:
> Hm. The right fix here is to actually use the cert for a long time, not
just to claim that we're using it for a long time. This fix doesn't help
so much if we're going to keep rotating our initially presented CA certs
so often.
>
Makes sense.
(When we roll out user-defined certificates (CA-signed or not) we should
probably start respecting their validity dates and stop trying to act
smart with advertised and internal certificate validities.)
>
> Also, using "exactly 365*24*60*60 seconds" as our idea of the length of
a year probably is more fingerprintable than rotating our certs too often.
When actual CAs sell certs, I believe they don't do it like that. Some of
them do stuff more along the times of timegm/gmtime manipulation -- some
so that notBefore is at 00:00:00 GMT and notAfter is 23:59:59 GMT.
Right.
>We should probably see what openssl self-signed certs tend to have in
this regard.
Hm, it seems like the default '-days' argument of req(1SSL) and x509(1SSL)
is '30', for thirty days of duration.
I'm not sure how HTTPS server operators who use self-signed certificates
generate them, and whether Apache provides them with a custom generation
script with a custom certificate duration.
We probably need to dive into the SSL observatory and look for self-signed
certificate durations.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/4583#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs