In light of the limited visibility of WHOIS, Wayne's suggestion of "... allow 
anyone to revoke by proving that they control the domain name using one of the 
BR 3.2.2.4 methods" is preferable as it is a bit more encompassing rather than 
restricting to to same validation process.  This also supports the idea of 
transparency around revocation processes.
_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to