We have a technical control in place for systems that issue S/MIME certs in 
this CA hierarchy.  Our systems use static cert templates from which end-entity 
certs are issued. Those templates include an EKU value, but do not use the 
serverAuth or anyExtendedKeyUsage values.
_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to