On 2019-03-02 01:49, George Macon via dev-security-policy wrote:

One specific question on this point: Why did the software permit setting
the approval scope to a public suffix (as defined by inclusion on the
public suffix list)? Could validation agent action set the approval
scope to some other two-label public suffix like co.uk?

I think this is highly unlikely seeing as this was a human error and unlike in-addr.arpa, people might know about .co.uk.

- Cynthia

_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to