All, This email concerns the criteria for assessing the mass revocation planning efforts of CA operators in MRSP section 6.1.3 <https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/#613-delayed-revocation>, which was written prior to the adoption of TLS BR section 5.7. <goog_94539820>1.2 by CA/Browser Forum Ballot SC-89 <https://cabforum.org/2025/07/22/ballot-sc-089-mass-revocation-planning/>.
I am proposing that we address Issue #299 <https://github.com/mozilla/pkipolicy/issues/299>, which is related to Issue #293 <https://github.com/mozilla/pkipolicy/issues/293> - eliminating duplication with CCADB/CABF BRs, by removing some requirements in section 6.1.3 that are now found in section 5.7.1.2 of the TLS BRs <https://cabforum.org/working-groups/server/baseline-requirements/requirements/#5712-mass-revocation-plans> . Here is a GitHub comparison for your review and comment: https://github.com/BenWilson-Mozilla/pkipolicy/commit/39c7e9eb8975a99a9314a0a2cea88ac9d255e19c . The proposed change aligns evaluation of compliance with the CA operator’s standard TLS BR audit and removes the implication that a separate third-party assessment is required. Please provide any comments or concerns. Thanks, Ben -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtabuoNOz-1RuQxFCRCZ-O87gUmRVBdZEvM_9Axb%2BuB88qw%40mail.gmail.com.
