The voting on amendment SC27v3 to the Basic Requirements, according to which certification authorities issue SSL certificates, has concluded. As a result, the amendment allowing DV or OV certificates to be issued for .onion domain names for hidden Tor services under certain conditions has been adopted.
Previously, only the issuance of EV certificates was permitted due to insufficient cryptographic strength of the algorithms associated with the domain names of hidden services. Once the amendment comes into effect, a validation method will be allowed in which the owner of a hidden service accessible via HTTP makes a change on the site requested by the certification authority, such as placing a file with specified content at a designated address.
As an alternative method available only for hidden services using version 3 onion addresses, it is also proposed to allow the signing of the certificate request with the same key used by the hidden service for Tor routing. To protect against abuse, this certificate request must include two special records containing random numbers generated by the certification authority and the service owner.
The amendment was supported by 9 out of 15 representatives of certification authorities and 4 out of 4 representatives of web browser companies. There were no votes against.
Source: linux.org.ru
