Re: StartCom & Qihoo Incidents

2016-10-27 Thread Erwann Abalea
Le jeudi 27 octobre 2016 09:55:09 UTC+2, Percy a écrit : > So this is it? Qihoo can continue to get away with this MITM browser? I'm afraid that can't be solved by Mozilla. Qihoo is free to sell or freely distribute their browser. ___ dev-security-polic

Re: Guang Dong Certificate Authority (GDCA) root inclusion request

2016-10-27 Thread Percy
"When facing any requirements of laws and regulations or any demands for undergoing legal process of court and other agencies, GDCA must provide confidential information in this CP" Can GDCA specify what other agencies are included? In China, many requests are relayed simply through a phone cal

Re: Guang Dong Certificate Authority (GDCA) root inclusion request

2016-10-27 Thread Han Yuwei
在 2016年10月27日星期四 UTC+8下午6:22:03,wangs...@gmail.com写道: > 在 2016年10月27日星期四 UTC+8上午8:09:06,Peter Kurrasch写道: > > I think these are both good points and my recommendation is that Mozilla > > deny GDCA's request for inclusion. > > > > > > We should not have to explain something as basic as document v

Re: Guang Dong Certificate Authority (GDCA) root inclusion request

2016-10-27 Thread Han Yuwei
在 2016年10月28日星期五 UTC+8上午2:12:32,Percy写道: > On Thursday, October 27, 2016 at 3:22:03 AM UTC-7, wangs...@gmail.com wrote: > > 在 2016年10月27日星期四 UTC+8上午8:09:06,Peter Kurrasch写道: > > > I think these are both good points and my recommendation is that Mozilla > > > deny GDCA's request for inclusion. > >

Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Kathleen Wilson
I have sent the email to the following CAs. Root Owner | # Certs still to add to Salesforce Actalis 2 Asseco Data Systems S.A. (previously Unizeto Certum)1 Atos3 Autoridad de Certificacion Firmaprofesional 6 Camerfirma 19 certSIGN6 China Internet Network Informatio

Re: Guang Dong Certificate Authority (GDCA) root inclusion request

2016-10-27 Thread Percy
On Thursday, October 27, 2016 at 3:22:03 AM UTC-7, wangs...@gmail.com wrote: > 在 2016年10月27日星期四 UTC+8上午8:09:06,Peter Kurrasch写道: > > I think these are both good points and my recommendation is that Mozilla > > deny GDCA's request for inclusion. > > > > > > We should not have to explain something

Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Kathleen Wilson
On Thursday, October 27, 2016 at 4:14:35 AM UTC-7, Rob Stradling wrote: > So, to ensure that no CA can claim that they didn't know, I'd like to > see the "must keep disclosing intermediates to Salesforce on an ongoing > basis" requirement explicitly stated: > 1. in the next version of the Mozilla

Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Rob Stradling
On 27/10/16 09:31, Gervase Markham wrote: > On 26/10/16 22:02, Kathleen Wilson wrote: >> Please see >> https://wiki.mozilla.org/CA:SalesforceCommunity#CA_Community_in_Salesforce >> and let me know if you still think we need to add a sentence to the >> wiki page stating that CAs are expected to ma

Re: Guang Dong Certificate Authority (GDCA) root inclusion request

2016-10-27 Thread wangsn1206
在 2016年10月27日星期四 UTC+8上午8:09:06,Peter Kurrasch写道: > I think these are both good points and my recommendation is that Mozilla deny > GDCA's request for inclusion. > > > We should not have to explain something as basic as document versioning and > version control. If GDCA can not demonstrate suff

Re: Technically Constrained Sub-CAs and the BRs

2016-10-27 Thread Gervase Markham
On 26/10/16 18:53, Ryan Sleevi wrote: > interpretation of #2. This is also why I support the mandatory > disclosure of TCSCs to Mozilla Salesforce, to ensure that the > Technical Constraints are properly implemented and conforming in > order for the CA to claim its exclusion. If we were to require

Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Gervase Markham
On 26/10/16 22:02, Kathleen Wilson wrote: > I agree that I should add a section about that to > https://wiki.mozilla.org/CA:SalesforceCommunity I don't agree that it > needs to be resolved before reminding these particular CAs about > their overdue action items. If they fall into that category, th

Re: StartCom & Qihoo Incidents

2016-10-27 Thread Percy
So this is it? Qihoo can continue to get away with this MITM browser? ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy