It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.
CAB has nothing to do with trust/distrust here. Its the Root CA Store Operators (Mozilla, Google, Apple, Microsoft, Adobe) which have to distrust here.
In other words: the CAB members would distrust the CA because the CA would be in violation of their individual root store policies, specifically the "you must follow the rules set by the CAB" part.
MisterMunchkin · · focus · HN ↗
evan_a_a · · focus · HN ↗
<a href="https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.2.5.pdf" rel="nofollow">https://cabforum.org/working-groups/server/baseline-requirem...
vg · · focus · HN ↗
crote · · focus · HN ↗