Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-13 Thread Martijn Katerbarg via Servercert-wg
2024 at 12:22 To: Ponds-White, Trev , CA/B Forum Server Certificate WG Public Discussion List , Tim Hollebeek , Christophe Bonjean Subject: Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements CAUTION: This email originated from outside

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-07 Thread Martijn Katerbarg via Servercert-wg
Discussion List ; Christophe Bonjean Subject: RE: [EXTERNAL] [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements There are a number of attack scenarios that cause network devices to crash/restart either as part of the attack, or as a consequence

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-06 Thread Ponds-White, Trev via Servercert-wg
; CA/B Forum Server Certificate WG Public Discussion List ; Christophe Bonjean Subject: RE: [EXTERNAL] [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements There are a number of attack scenarios that cause network devices to crash/restart either

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-06 Thread Tim Hollebeek via Servercert-wg
6, 2024 12:59 PM To: Christophe Bonjean ; CA/B Forum Server Certificate WG Public Discussion List Subject: Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements I had the same thought about firewall rules vs configuration changes being

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-06 Thread Ponds-White, Trev via Servercert-wg
: Tuesday, February 6, 2024 5:39 AM To: Ponds-White, Trev ; CA/B Forum Server Certificate WG Public Discussion List Subject: RE: [EXTERNAL] [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements I agree with Trev’s perspective. A few comments

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-06 Thread Christophe Bonjean via Servercert-wg
Forum Server Certificate WG Public Discussion List ; Clint Wilson Subject: Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements I think “router and firewall activities” are solutions that don’t identify the problem we are trying to solve

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-05 Thread Ponds-White, Trev via Servercert-wg
: [EXTERNAL] [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Hi Clint, Thanks

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-05 Thread Martijn Katerbarg via Servercert-wg
terbarg , ServerCert CA/BF Subject: Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements Hi Martijn, Thanks for sending this out for discussion. Just a few comments at this point: 1. I’m not sure the wording "Router and firewall activities

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-02 Thread Aaron Gable via Servercert-wg
On Fri, Feb 2, 2024, 16:13 Clint Wilson via Servercert-wg < servercert-wg@cabforum.org> wrote: > Hi Martijn, > > Thanks for sending this out for discussion. Just a few comments at this > point: > > >1. I’m not sure the wording "Router and firewall activities" is >considered an unspecified

Re: [Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-02-02 Thread Clint Wilson via Servercert-wg
Hi Martijn, Thanks for sending this out for discussion. Just a few comments at this point: I’m not sure the wording "Router and firewall activities" is considered an unspecified term, and leaves the exact definition and scope up to the CA, however” is necessary or even really helpful. I think

[Servercert-wg] [Discussion Period Begins]: SC-69 Clarify router and firewall logging requirements

2024-01-29 Thread Martijn Katerbarg via Servercert-wg
Summary: This ballot aims to clarify what data needs to be logged as part of the "Firewall and router activities" logging requirement in the Baseline Requirements. This ballot is proposed by Martijn Katerbarg (Sectigo) and endorsed by Daniel Jeffery (Fastly) and Ben Wilson (Mozilla). ---