Hi Tim,
Are you referring to this bug that was discovered last year? 
https://www.mozilla.org/en-US/security/advisories/mfsa2017-24/#CVE-2017-7838

Thanks,

Corey Bonnell
Senior Software Engineer
t: +1 412.395.2233

Trustwave | SMART SECURITY ON DEMAND
www.trustwave.com<http://www.trustwave.com/>

From: Public <[email protected]> on behalf of Tim Hollebeek via 
Public <[email protected]>
Reply-To: Tim Hollebeek <[email protected]>, CA/Browser Forum Public 
Discussion List <[email protected]>
Date: Wednesday, May 23, 2018 at 1:57 PM
To: Ryan Sleevi <[email protected]>
Cc: CA/Browser Forum Public Discussion List <[email protected]>
Subject: Re: [cabfpub] Question about CN and SAN encoding

I agree.  The ballot is not affected at all (it wasn’t mentioned in the first 
two sentences).

I believe your first two sentences are correct with respect to current versions 
of major browsers, but need a small caveat w.r.t. older versions of Firefox.

Corey can correct me if I’m wrong, but I was thinking of the Firefox display 
bugs we stumbled on when he found some spoofing issues with respect to display 
of xn-- domain components in Firefox.  Older versions of Firefox (circa last 
year?) had some errors in their logic.

Like I said, they’re pretty minor, but worth noting.

-Tim

From: Ryan Sleevi [mailto:[email protected]]
Sent: Wednesday, May 23, 2018 11:15 AM
To: Tim Hollebeek <[email protected]>
Cc: CA/Browser Forum Public Discussion List <[email protected]>; García 
Jimeno, Oscar <[email protected]>
Subject: Re: [cabfpub] Question about CN and SAN encoding



On Wed, May 23, 2018 at 11:06 AM, Tim Hollebeek 
<[email protected]<mailto:[email protected]>> wrote:
With regards to the first two sentences, Firefox had some bugs in this area 
pretty recently, so if you aren’t on the latest version, you might experience 
issues.  They were relatively minor, though.

Could you provide a citation for this? I actually carefully watch all of those 
changes, and am not aware of any recent bugs that would overlap with the ballot 
or question. It's possible that you're referring to the logic for when A-Label 
to U-Labels are displayed, but that, if anything, is a very clear argument in 
favor of Ballot 202, and against U-Labels within CNs.

_______________________________________________
Public mailing list
[email protected]
https://cabforum.org/mailman/listinfo/public

Reply via email to