[Servercert-wg] Discussion Period Begins - Ballot SC-071: Subscriber Agreement and Terms of Use Consolidation

2024-04-11 Thread Dustin Hollenback via Servercert-wg
Purpose of Ballot SC-071 This ballot proposes updates to the Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates related to Subscriber Agreements and Terms of Use. It combines the requirements for both into only the Subscriber Agreement and clarifies the

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-11 Thread Clint Wilson via Servercert-wg
Hi Aaron, Your proposed phrasing sounds good to me and matches what I had in mind as the end result of the changes represented in Set 1, just structured slightly differently. Cheers, -Clint > On Apr 11, 2024, at 9:47 AM, Aaron Gable wrote: > > On Thu, Apr 11, 2024 at 9:12 AM Clint Wilson

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-11 Thread Aaron Gable via Servercert-wg
On Thu, Apr 11, 2024 at 9:12 AM Clint Wilson via Servercert-wg < servercert-wg@cabforum.org> wrote: > In other words, I believe it satisfactory to establish a constrained set > of Debian weak keys which CAs must block (rather than leaving the > requirement fully open-ended), but I don’t believe

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-11 Thread Clint Wilson via Servercert-wg
Hi Wayne, Agreed, your proposal [1] is basically what I was describing; I only added that it would be useful, in my mind, to add a repository usable by Certificate Issuers (but not required to be used) similar to what we’ve provided for ROCA and Close Primes. However, based on the discussion