> -----Original Message----- > From: Gervase Markham [mailto:g...@mozilla.org] > Sent: Friday, August 18, 2017 9:42 AM > To: Doug Beattie <doug.beat...@globalsign.com>; richmoor...@gmail.com; > mozilla-dev-security-pol...@lists.mozilla.org > Subject: Re: Responding to a misissuance > > On 18/08/17 13:03, Doug Beattie wrote: > > And if there is any guidance on processing misissuance reports for > > Name constrained sub-CA vs. not name constrained, that would be > > helpful also. > > What parts of a response do you think might be different for name- > constrained sub-CAs?
Technically constrained CAs need to follow the BRs, but the "damage" they can do is limited to the set of domains they are constrained to, so I had assumed a different process might result. But, given your pointed question, I can’t actually come up with what would be different. > Gerv _______________________________________________ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy