Re: [cabfpub] Random value reuse

2017-08-09 Thread Ben Wilson via Public
; geo...@apple.com; CA/Browser Forum Public Discussion List <public@cabforum.org>; Gervase Markham <g...@mozilla.org>; Rich Smith <richard.sm...@comodo.com> Subject: Re: [cabfpub] Random value reuse In methods 2 & 4 it goes to the domain contact or a role account at th

Re: [cabfpub] Random value reuse

2017-08-09 Thread Geoff Keating via Public
apple.com > Cc: CA/Browser Forum Public Discussion List <public@cabforum.org>; Gervase > Markham <g...@mozilla.org>; Jeremy Rowley <jeremy.row...@digicert.com>; Rich > Smith <richard.sm...@comodo.com>; Peter Bowen <p...@amzn.com> > Subject: RE: [cabfpub

Re: [cabfpub] Random value reuse

2017-08-09 Thread Jeremy Rowley via Public
com>; geo...@apple.com; CA/Browser Forum Public Discussion List <public@cabforum.org>; Gervase Markham <g...@mozilla.org>; Rich Smith <richard.sm...@comodo.com> Subject: Re: [cabfpub] Random value reuse In methods 2 & 4 it goes to the domain contact or a role account at the do

Re: [cabfpub] Random value reuse

2017-08-09 Thread Jeremy Rowley via Public
<ben.wil...@digicert.com>; geo...@apple.com Cc: CA/Browser Forum Public Discussion List <public@cabforum.org> Subject: Re: [cabfpub] Random value reuse It raises a lot of questions though. Can I email the Random Value to a reseller who forwards it on to the end entity? Can I display it

Re: [cabfpub] Random value reuse

2017-08-09 Thread Peter Bowen via Public
: geo...@apple.com; CA/Browser Forum Public Discussion List > <public@cabforum.org>; Gervase Markham <g...@mozilla.org>; Jeremy Rowley > <jeremy.row...@digicert.com>; Rich Smith <richard.sm...@comodo.com> > Subject: Re: [cabfpub] Random value reuse > > That

Re: [cabfpub] Random value reuse

2017-08-09 Thread Jeremy Rowley via Public
pple.com] Sent: Wednesday, August 9, 2017 3:30 PM To: Ben Wilson <ben.wil...@digicert.com> Cc: CA/Browser Forum Public Discussion List <public@cabforum.org>; Gervase Markham <g...@mozilla.org>; Jeremy Rowley <jeremy.row...@digicert.com>; Rich Smith <richard.sm...@comod

Re: [cabfpub] Random value reuse

2017-08-09 Thread Peter Bowen via Public
t; > Cc: CA/Browser Forum Public Discussion List <public@cabforum.org>; Gervase > Markham <g...@mozilla.org>; Jeremy Rowley <jeremy.row...@digicert.com>; Rich > Smith <richard.sm...@comodo.com>; Peter Bowen <p...@amzn.com> > Subject: Re: [cabfpub] Random value

Re: [cabfpub] Random value reuse

2017-08-09 Thread Geoff Keating via Public
.wil...@digicert.com>; CA/Browser Forum Public Discussion > List <public@cabforum.org> > Cc: Gervase Markham <g...@mozilla.org>; Jeremy Rowley > <jeremy.row...@digicert.com>; Rich Smith <richard.sm...@comodo.com>; Peter > Bowen <p...@amzn.com&

Re: [cabfpub] Random value reuse

2017-08-09 Thread Ben Wilson via Public
on List <public@cabforum.org> Cc: Gervase Markham <g...@mozilla.org>; Jeremy Rowley <jeremy.row...@digicert.com>; Rich Smith <richard.sm...@comodo.com>; Peter Bowen <p...@amzn.com> Subject: Re: [cabfpub] Random value reuse I think that’s where the ‘single communication

Re: [cabfpub] Random value reuse

2017-08-09 Thread Geoff Keating via Public
[mailto:public-boun...@cabforum.org] On Behalf Of Gervase > Markham via Public > Sent: Monday, July 31, 2017 9:02 AM > To: Jeremy Rowley <jeremy.row...@digicert.com>; CA/Browser Forum Public > Discussion List <public@cabforum.org>; Rich Smith <richard.sm...@comodo.com>;

Re: [cabfpub] Random value reuse

2017-08-09 Thread Ben Wilson via Public
ion List <public@cabforum.org>; Rich Smith <richard.sm...@comodo.com>; 'Peter Bowen' <p...@amzn.com> Subject: Re: [cabfpub] Random value reuse On 28/07/17 14:53, Jeremy Rowley via Public wrote: > I think the random value should be tied to a single communication > without

Re: [cabfpub] Random value reuse

2017-07-31 Thread Gervase Markham via Public
On 28/07/17 14:53, Jeremy Rowley via Public wrote: > I think the random value should be tied to a single communication > without reuse. For example, a single email sent to the constructed > emails, a single API call, a single phone call, etc. The random value > shouldn’t be tied to a method, but

Re: [cabfpub] Random value reuse

2017-07-28 Thread Jeremy Rowley via Public
Public Discussion List' <public@cabforum.org>; Jeremy Rowley <jeremy.row...@digicert.com> Subject: RE: [cabfpub] Random value reuse Peter, You make good points. How about something along the lines of: The CA SHALL NOT share the random value generated for methods 2 and/or 4 with the

Re: [cabfpub] Random value reuse

2017-07-28 Thread Rich Smith via Public
[mailto:public-boun...@cabforum.org] On Behalf Of Peter Bowen via Public Sent: Wednesday, July 26, 2017 12:34 AM To: Jeremy Rowley <jeremy.row...@digicert.com>; CA/Browser Forum Public Discussion List <public@cabforum.org> Subject: Re: [cabfpub] Random value reuse Jeremy, This is an

Re: [cabfpub] Random value reuse

2017-07-28 Thread Rich Smith via Public
:21 PM To: CA/Browser Forum Public Discussion List <public@cabforum.org> Subject: [cabfpub] Random value reuse An interesting question came up today in connection with random values used for validation. Methods 2, 4, 6, 7, and 10 permit use of a random values. Methods 2 and 4, require a