{"id":2264,"date":"2017-10-31T04:47:25","date_gmt":"2017-10-31T11:47:25","guid":{"rendered":"https:\/\/blog.mozilla.org\/security\/?p=2264"},"modified":"2017-10-31T04:50:06","modified_gmt":"2017-10-31T11:50:06","slug":"statement-digicerts-proposed-purchase-symantec","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/","title":{"rendered":"Statement on DigiCert\u2019s Proposed Purchase of Symantec&#8217;s CA"},"content":{"rendered":"<p>Mozilla\u2019s Root Store Program has taken the position that trust is not automatically transferable between organizations. This is specifically stated in section 8 of our <a href=\"http:\/\/www.mozilla.org\/projects\/security\/certs\/policy\/\">Root Store Policy v2.5<\/a>, which details how Mozilla handles transfers of root certificates between organizations. Mozilla has taken an interest in such transfers, and there is the potential for trust adjustments based on the particular circumstances.<\/p>\n<p>The CA DigiCert has announced that it is <a href=\"https:\/\/www.digicert.com\/news\/digicert-to-acquire-symantec-website-security-business\/\">in negotiations to acquire the CA business of Symantec<\/a>. This announcement was made following the decision of Mozilla and other root store programs to <a href=\"https:\/\/groups.google.com\/a\/chromium.org\/d\/msg\/blink-dev\/eUAKwjihhBs\/El1mH8S6AwAJ\">phase out trust in Symantec\u2019s root certificates<\/a>, based on a <a href=\"https:\/\/wiki.mozilla.org\/CA:Symantec_Issues\">detailed investigation<\/a> of their old and large CA hierarchies and their behaviour and practices over the past few years. There are no plans to change this phase-out of trust in the roots owned by Symantec.<\/p>\n<p>While Mozilla does not intend to micro-manage any CA, the final arrangements for management and processes and infrastructure to be used by the combined company is of interest and potential concern to us. It would not be appropriate for a CA to escape root program sanction by restructuring, or by purchasing another CA through M&amp;A and continuing operations under that CA\u2019s name, essentially unchanged. And examination of historical corporate merger and acquisition activity, including deals involving Symantec, show that it\u2019s possible for an M&amp;A billed as the \u201cpurchase of B by A\u201d to end up with name A and yet be mostly managed by the executives of B.<\/p>\n<p>Representatives of DigiCert have sought guidance from us on the type of arrangements which would and would not cause us concern. In a good faith effort to answer that enquiry, we can make the following, non-exhaustive statements of what would cause Mozilla concern.<\/p>\n<ul>\n<li>We would be concerned if the combined company continued to operate significant pieces of Symantec\u2019s old infrastructure as part of their day-to-day issuance of publicly-trusted certificates.<\/li>\n<li>We would be concerned if Symantec validation and operations personnel continued their roles without retraining in DigiCert methods and culture.<\/li>\n<li>We would be concerned if Symantec processes appeared to displace DigiCert processes.<\/li>\n<li>We would be concerned if the management of the combined company, particularly that part of it providing technical and policy direction and oversight of the PKI, were to appear as if Symantec were the controlling CA organization in the merger.<\/li>\n<\/ul>\n<p>We hope that this provides useful guidance about our concerns, and note that our final opinion of the trustworthiness of the resulting entity will depend on the facts and behavior of the resulting organization. Mozilla reserves the right to include or exclude organizations or root certificates from our root store at our sole discretion. However, if the M&amp;A activity \u00a0moves forward, we hope that the list above \u00a0will be helpful to DigiCert in planning for a future harmonious working relationship with the Mozilla Root Program.<\/p>\n<p>Gervase Markham<br \/>\nKathleen Wilson<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mozilla\u2019s Root Store Program has taken the position that trust is not automatically transferable between organizations. This is specifically stated in section 8 of our Root Store Policy v2.5, which &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/\">Read more<\/a><\/p>\n","protected":false},"author":909,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47,45538],"tags":[],"coauthors":[204014],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Statement on DigiCert\u2019s Proposed Purchase of Symantec&#039;s CA - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Gervase Markham\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/\",\"name\":\"Statement on DigiCert\u2019s Proposed Purchase of Symantec's CA - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2017-10-31T11:47:25+00:00\",\"dateModified\":\"2017-10-31T11:50:06+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/c72e0fa2d60987fc986e514157ace712\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Statement on DigiCert\u2019s Proposed Purchase of Symantec&#8217;s CA\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/c72e0fa2d60987fc986e514157ace712\",\"name\":\"Gervase Markham\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/978c7725c187ec60b62fdfbaeab3da52\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/559c3cf31c98a95b23421186b78df500?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/559c3cf31c98a95b23421186b78df500?s=96&d=identicon&r=g\",\"caption\":\"Gervase Markham\"},\"description\":\"Gervase Markham works for Mozilla, where he tries to know just enough about everything to be dangerous. He likes solving complex problems which have social, technical, policy, human and legal aspects. He is a follower of Jesus, a lover of good cheese, and a supporter of Liverpool FC.\",\"sameAs\":[\"http:\/\/www.gerv.net\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Statement on DigiCert\u2019s Proposed Purchase of Symantec's CA - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/","twitter_misc":{"Written by":"Gervase Markham","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/","url":"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/","name":"Statement on DigiCert\u2019s Proposed Purchase of Symantec's CA - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2017-10-31T11:47:25+00:00","dateModified":"2017-10-31T11:50:06+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/c72e0fa2d60987fc986e514157ace712"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2017\/10\/31\/statement-digicerts-proposed-purchase-symantec\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Statement on DigiCert\u2019s Proposed Purchase of Symantec&#8217;s CA"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/c72e0fa2d60987fc986e514157ace712","name":"Gervase Markham","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/978c7725c187ec60b62fdfbaeab3da52","url":"https:\/\/secure.gravatar.com\/avatar\/559c3cf31c98a95b23421186b78df500?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/559c3cf31c98a95b23421186b78df500?s=96&d=identicon&r=g","caption":"Gervase Markham"},"description":"Gervase Markham works for Mozilla, where he tries to know just enough about everything to be dangerous. He likes solving complex problems which have social, technical, policy, human and legal aspects. He is a follower of Jesus, a lover of good cheese, and a supporter of Liverpool FC.","sameAs":["http:\/\/www.gerv.net\/"]}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2264"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/909"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=2264"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2264\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=2264"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=2264"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=2264"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=2264"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}