Comment 50 for bug 310999

Revision history for this message
In , Sam Johnston (samj) wrote :

My point is that the cracks in the "CA system as a whole" run *far* deeper than just one RA - in the past days we've seen critical technical vulnerabilities (MD5), a very serious process fault (CertStar) and an equally serious (if not deliberately negligent) logic flaw (StartCom). It seems to me that the PKI in general is profoundly sick and it's time to start looking at alternatives while keeping the needs of the user in mind (rather than those of the vendors).

Back on topic, the RA in question currently states[1]:

"Unable to Process Orders

Due to technical issues we are unable to process orders at this time. We are working hard to resolve the issue and apologize for any convenience caused.

Please check back later."

So some steps have been taken towards rectification, but I'm not aware of any retrospective efforts (eg re-validation by Comodo of certs issued by CertStar).

1. https://secure.certstar.com/ordering/?page=register&psf=ssldv&currency=eur