Re: Is Mozilla actively working to introduce CAless TLS public key checking?

2012-01-12 Thread Daniel Veditz
On 1/12/12 12:10 AM, Henri Sivonen wrote: > Is Mozilla actively working on a TLS public key checking system that > has real trust agility (not DNSsec!) and that doesn't require CAs to > work (but that can work in parallel with the CA system)? Not "actively", no. It's too early to determine if that

Re: Policy discussion list that is read-only for the public

2012-01-12 Thread Daniel Veditz
On 1/11/12 7:38 PM, Kyle Hamilton wrote: > Right now, the security group (particularly the participants in > the CABF from Mozilla) There have been zero discussions about CABF stuff on the private security-group mailing list. The only time I recall PKI-in-general topics coming up is in the heat of

Is Mozilla actively working to introduce CAless TLS public key checking?

2012-01-12 Thread Henri Sivonen
After reading about CA compromises again and again, I am wondering: Is Mozilla actively working on a TLS public key checking system that has real trust agility (not DNSsec!) and that doesn't require CAs to work (but that can work in parallel with the CA system)? Building Convergence into Firefox