That one, and the related ones Ryan mentioned.  It’s a fun one.  Thanks for 
digging it up.

 

-Tim

 

From: Corey Bonnell [mailto:[email protected]] 
Sent: Thursday, May 24, 2018 10:58 AM
To: Tim Hollebeek <[email protected]>; CA/Browser Forum Public 
Discussion List <[email protected]>; Ryan Sleevi <[email protected]>
Subject: Re: [cabfpub] Question about CN and SAN encoding

 

Hi Tim,

Are you referring to this bug that was discovered last year? 
https://www.mozilla.org/en-US/security/advisories/mfsa2017-24/#CVE-2017-7838

 

Thanks,

 

Corey Bonnell

Senior Software Engineer

t: +1 412.395.2233

 

Trustwave | SMART SECURITY ON DEMAND <http://www.trustwave.com/> 
www.trustwave.com

 

From: Public <[email protected] <mailto:[email protected]> 
> on behalf of Tim Hollebeek via Public <[email protected] 
<mailto:[email protected]> >
Reply-To: Tim Hollebeek <[email protected] 
<mailto:[email protected]> >, CA/Browser Forum Public Discussion List 
<[email protected] <mailto:[email protected]> >
Date: Wednesday, May 23, 2018 at 1:57 PM
To: Ryan Sleevi <[email protected] <mailto:[email protected]> >
Cc: CA/Browser Forum Public Discussion List <[email protected] 
<mailto:[email protected]> >
Subject: Re: [cabfpub] Question about CN and SAN encoding

 

I agree.  The ballot is not affected at all (it wasn’t mentioned in the first 
two sentences).

 

I believe your first two sentences are correct with respect to current versions 
of major browsers, but need a small caveat w.r.t. older versions of Firefox.

 

Corey can correct me if I’m wrong, but I was thinking of the Firefox display 
bugs we stumbled on when he found some spoofing issues with respect to display 
of xn-- domain components in Firefox.  Older versions of Firefox (circa last 
year?) had some errors in their logic.

 

Like I said, they’re pretty minor, but worth noting.

 

-Tim

 

From: Ryan Sleevi [mailto:[email protected]] 
Sent: Wednesday, May 23, 2018 11:15 AM
To: Tim Hollebeek <[email protected] 
<mailto:[email protected]> >
Cc: CA/Browser Forum Public Discussion List <[email protected] 
<mailto:[email protected]> >; García Jimeno, Oscar <[email protected] 
<mailto:[email protected]> >
Subject: Re: [cabfpub] Question about CN and SAN encoding

 

 

 

On Wed, May 23, 2018 at 11:06 AM, Tim Hollebeek <[email protected] 
<mailto:[email protected]> > wrote:

With regards to the first two sentences, Firefox had some bugs in this area 
pretty recently, so if you aren’t on the latest version, you might experience 
issues.  They were relatively minor, though.

 

Could you provide a citation for this? I actually carefully watch all of those 
changes, and am not aware of any recent bugs that would overlap with the ballot 
or question. It's possible that you're referring to the logic for when A-Label 
to U-Labels are displayed, but that, if anything, is a very clear argument in 
favor of Ballot 202, and against U-Labels within CNs.

 

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Public mailing list
[email protected]
https://cabforum.org/mailman/listinfo/public

Reply via email to