[Servercert-wg] Weekly github digest (Server Certificate Working Group)

2024-03-09 Thread Infrastructure Bot via Servercert-wg
Pull requests - * cabforum/servercert (+0/-1/0) 1 pull requests merged: - SC68: Allow VATEL and VATXI https://github.com/cabforum/servercert/pull/478 [ballot] Repositories tracked by this digest: --- *

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-03-09 Thread Dimitris Zacharopoulos (HARICA) via Servercert-wg
FWIW, I think in the recent years, it was mostly security researchers that attempted to request certificates with Debian weak keys to test if a CA was properly blocking them. If an Applicant uses an outdated OS that generates weak keys, imagine the actual web server or other software that

Re: [Servercert-wg] [Voting Period Begins]: SC65: Convert EVGs into RFC 3647 format v2

2024-03-09 Thread Dimitris Zacharopoulos (HARICA) via Servercert-wg
Thank you for providing the correct comparison, this is helpful. I'm not sure what kind of precedent we set by voting on a normative redline that points to something else than what we actually intend to vote on. However, it seems that more focus is on the EVG which is clearer. HARICA changes