All,

This email concerns the criteria for assessing the mass revocation planning
efforts of CA operators in MRSP section 6.1.3
<https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/#613-delayed-revocation>,
which was written prior to the adoption of TLS BR section 5.7.
<goog_94539820>1.2 by CA/Browser Forum Ballot SC-89
<https://cabforum.org/2025/07/22/ballot-sc-089-mass-revocation-planning/>.

I am proposing that we address Issue #299
<https://github.com/mozilla/pkipolicy/issues/299>, which is related to Issue
#293 <https://github.com/mozilla/pkipolicy/issues/293> - eliminating
duplication with CCADB/CABF BRs, by removing some requirements in section
6.1.3 that are now found in section 5.7.1.2 of the TLS BRs
<https://cabforum.org/working-groups/server/baseline-requirements/requirements/#5712-mass-revocation-plans>
.

Here is a GitHub comparison for your review and comment:
https://github.com/BenWilson-Mozilla/pkipolicy/commit/39c7e9eb8975a99a9314a0a2cea88ac9d255e19c
.

The proposed change aligns evaluation of compliance with the CA operator’s
standard TLS BR audit and removes the implication that a separate
third-party assessment is required.

Please provide any comments or concerns.

Thanks,
Ben

-- 
You received this message because you are subscribed to the Google Groups 
"[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtabuoNOz-1RuQxFCRCZ-O87gUmRVBdZEvM_9Axb%2BuB88qw%40mail.gmail.com.

Reply via email to