{"id":63,"date":"2016-11-01T15:19:51","date_gmt":"2016-11-01T07:19:51","guid":{"rendered":"https:\/\/www.sslcert.com.hk\/blog\/?p=63"},"modified":"2017-05-31T17:25:12","modified_gmt":"2017-05-31T09:25:12","slug":"google-firefox-and-apple-distrust-wosign-and-startcom-certificates-in-2017-2","status":"publish","type":"post","link":"https:\/\/www.sslcert.com.hk\/blog\/zh\/2016\/11\/01\/google-firefox-and-apple-distrust-wosign-and-startcom-certificates-in-2017-2\/","title":{"rendered":"Google, Firefox\u548cApple\u57282017\u5e74\u4e0d\u4fe1\u4efbWoSign\u548cStartCom\u8bc1\u4e66"},"content":{"rendered":"<p><\/p>\n<p>\u5982\u679c\u60a8\u4f7f\u7528StartCom (StartSSL) \u6216WoSign\u8bc1\u4e66, \u662f\u65f6\u5019\u9700\u8981\u66f4\u53d8\u4e86!<\/p>\n<p> Mozilla\u4e8e2016\u5e7410\u670824\u65e5\u5ba3\u5e03, \u4eceFirefox 51\u5f00\u59cb, WoSign\u548cStartCom\u53d1\u884c\u7684\u8bc1\u4e66\u5c06\u4e0d\u88ab\u4fe1\u4efb.<\/p>\n<p> Google\u4e5f\u4e8e2016\u5e7410\u670831\u65e5\u5ba3\u5e03, \u4ece2017\u5e741\u6708Chrome 56\u5f00\u59cb, Chrome\u5c06\u4e0d\u4fe1\u4efb\u8ba4\u8bc1\u673a\u6784\u7b7e\u53d1\u7684\u8bc1\u4e66 &#8211; WoSign\u548cStartCom, \u4ed6\u4eec\u4e0d\u7b26\u5408\u8ba4\u8bc1\u673a\u6784\u7684\u671f\u671b\u6807\u51c6.<\/p>\n<p> \u4e24\u5bb6\u516c\u53f8\u90fd\u516c\u5f00\u8c34\u8d23WoSign\u6545\u610f\u9519\u8bef\u53d1\u51fa\u8bc1\u4e66, \u4ee5\u907f\u5f00\u6d4f\u89c8\u5668\u9650\u5236\u548cCA\u8981\u6c42, \u4ed6\u4eec\u8fd8\u6307\u8d23WoSign\u6536\u8d2dStartCom, WoSign\u548cStartCom\u7ba1\u7406\u5c42\u79ef\u6781\u5c1d\u8bd5\u8bef\u5bfc\u6d4f\u89c8\u5668\u793e\u7fa4\u5173\u4e8e\u8fd9\u4e24\u5bb6\u516c\u53f8\u7684\u6536\u8d2d\u548c\u5173\u7cfb.<\/p>\n<p> \u6700\u53ef\u6015\u7684\u662fWoSign\u7684\u8bef\u53d1\u8bc1\u4e66. GitHub\u7684\u5b89\u5168\u5c0f\u7ec4\u4e8e2016\u5e748\u670817\u65e5\u901a\u77e5Google, WoSign\u672a\u7ecf\u6388\u6743\u5c31\u5411GitHub\u7684\u5176\u4e2d\u4e00\u4e2a\u57df\u540d\u9881\u53d1\u4e86\u8bc1\u4e66. Google\u4e0eMozilla\u548c\u5b89\u5168\u793e\u533a\u5408\u4f5c, \u53d1\u73b0\u4e86\u8bb8\u591a\u7c7b\u4f3c\u7684\u6848\u4f8b.<\/p>\n<p> Mozilla\u7279\u522b\u53d1\u5e03\u4e8613\u9875\u7684\u62a5\u544a, \u89e3\u91ca\u4e86WoSign\u548cStartCom\u6240\u63d0\u51fa\u7684\u4e25\u91cd\u95ee\u9898. Mozilla\u53d1\u73b0WoSign\u66fe\u7ecf\u628aSSL\u8bc1\u4e66\u65e5\u671f\u6539\u5230\u8f83\u65e9\u65f6\u95f4, \u4ee5\u907f\u5f00CA\u57282016\u5e741\u67081\u65e5\u4e4b\u524d\u505c\u6b62\u53d1\u5e03SHA-1 SSL\u8bc1\u4e66\u7684\u622a\u6b62\u65e5\u671f.<\/p>\n<p> Google\u8868\u793a, \u4eceChrome 56\u5f00\u59cb\u5c06\u57282016\u5e7410\u670821\u65e5\u4e4b\u540e\u4e0d\u4fe1\u4efbWoSign\u548cStartCom\u8bc1\u4e66. \u5728\u6b64\u65e5\u671f\u4e4b\u524d\u53d1\u884c\u7684\u8bc1\u4e66, \u5982\u679c\u9075\u5b88Chrome\u653f\u7b56\u7684Certificate Transparency, \u6709\u53ef\u80fd\u4f1a\u7ee7\u7eed\u53d7\u5230\u4fe1\u8d56.<\/p>\n<p> \u82f9\u679c\u516c\u53f8\u5ba3\u5e03\u5c06\u963b\u622a\u7531WoSign CA Free SSL Certificate G2\u4e2d\u7ee7CA\u9881\u53d1\u7684\u8bc1\u4e66.<\/p>\n<p> \u5f53\u6211\u4eec\u8c08\u8bba\u5230SSL\u8bc1\u4e66, \u5b89\u5168\u6027\u662f\u6700\u91cd\u8981\u7684. \u5411\u4e00\u4e9b\u4e0d\u9075\u7167\u56fd\u9645\u6807\u51c6\u7684\u8bc1\u4e66\u9881\u53d1\u673a\u6784(CA)\u8d2d\u4e70SSL\u8bc1\u4e66, \u6216\u662f\u4f7f\u7528\u514d\u8d39\u7684SSL\u5e76\u4e0d\u662f\u4e00\u4e2a\u597d\u9009\u62e9. \u4e0d\u4f46\u4f1a\u628a\u4f60\u7684\u7f51\u7ad9\u548c\u5ba2\u6237\u7684\u8d44\u6599\u653e\u5230\u4e00\u4e2a\u5371\u9669\u7684\u4f4d\u7f6e\u4e0a, \u66f4\u53ef\u80fd\u5bfc\u81f4\u4f60\u7684\u7f51\u7ad9\u51fa\u73b0\u9519\u8bef\u5413\u8dd1\u4f60\u7684\u5ba2\u6237. \u5982\u679c\u4f60\u8fd8\u5728\u4f7f\u7528\u8fd9\u4e9b\u8bc1\u4e66, \u7acb\u5373\u8f6c\u7528\u4e00\u4e9b\u56fd\u9645\u5927\u54c1\u724c\u5982Symantec, Geotrust, Thawte, RapidSSL, Comodo\u7684\u8bc1\u4e66\u5427, \u8fd9\u53ef\u8ba9\u4f60\u51cf\u5c11\u5f88\u591a\u70e6\u607c\u548c\u63d0\u9ad8\u4f60\u7684\u7f51\u7ad9\u5b89\u5168\u6027.<\/p>\n<p> \u53c2\u8003:<br \/>\n https:\/\/security.googleblog.com\/2016\/10\/distrusting-wosign-and-startcom.html<br \/>\n https:\/\/blog.mozilla.org\/security\/2016\/10\/24\/distrusting-new-wosign-and-startcom-certificates\/<br \/>\n https:\/\/support.apple.com\/en-us\/HT204132<\/p>\n<p><\/p>","protected":false},"excerpt":{"rendered":"<p>\u5982\u679c\u60a8\u4f7f\u7528StartCom (StartSSL) \u6216WoSign\u8bc1\u4e66, \u662f\u65f6\u5019\u9700\u8981\u66f4\u53d8\u4e86! Mozilla\u4e8e2016\u5e7410\u670824\u65e5\u5ba3\u5e03, \u4eceFirefox 51\u5f00\u59cb, WoSign\u548cStartCom\u53d1\u884c\u7684\u8bc1\u4e66\u5c06\u4e0d\u88ab\u4fe1\u4efb. Google\u4e5f\u4e8e2016\u5e7410\u670831\u65e5\u5ba3\u5e03, \u4ece2017\u5e741\u6708Chrome 56\u5f00\u59cb, Chrome\u5c06\u4e0d\u4fe1\u4efb\u8ba4\u8bc1\u673a\u6784\u7b7e\u53d1\u7684\u8bc1\u4e66 &#8211; WoSign\u548cStartCom, \u4ed6\u4eec\u4e0d\u7b26\u5408\u8ba4\u8bc1\u673a\u6784\u7684\u671f\u671b\u6807\u51c6. \u4e24\u5bb6\u516c\u53f8\u90fd\u516c\u5f00\u8c34\u8d23WoSign\u6545\u610f\u9519\u8bef\u53d1\u51fa\u8bc1\u4e66, \u4ee5\u907f\u5f00\u6d4f\u89c8\u5668\u9650\u5236\u548cCA\u8981\u6c42, \u4ed6\u4eec\u8fd8\u6307\u8d23WoSign\u6536\u8d2dStartCom, WoSign\u548cStartCom\u7ba1\u7406\u5c42\u79ef\u6781\u5c1d\u8bd5\u8bef\u5bfc\u6d4f\u89c8\u5668\u793e\u7fa4\u5173\u4e8e\u8fd9\u4e24\u5bb6\u516c\u53f8\u7684\u6536\u8d2d\u548c\u5173\u7cfb. \u6700\u53ef\u6015\u7684\u662fWoSign\u7684\u8bef\u53d1\u8bc1\u4e66.<\/p>\n","protected":false},"author":1,"featured_media":89,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[9],"tags":[32,33,34],"_links":{"self":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/posts\/63"}],"collection":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/comments?post=63"}],"version-history":[{"count":0,"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/posts\/63\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/media\/89"}],"wp:attachment":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/media?parent=63"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/categories?post=63"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/zh\/wp-json\/wp\/v2\/tags?post=63"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}