Re: Exceptions to 1024-bit cert revocation requirement

2013-12-12 Thread Jan Schejbal
Am 2013-12-11 23:31, schrieb Kathleen Wilson: I am inclined to grant more time to CAs for customers who are working hard to transition off of 1024-bit certs, but need a little more time to complete their transition. We need to distinguish between roots, intermediates and end-entity

Re: Revoking Trust in one ANSSI Certificate

2013-12-12 Thread Jan Schejbal
Am 2013-12-11 23:59, schrieb Gervase Markham: Look again. It seems that it now contains 1106 certificates (!), with widely varying revocation dates. Can't confirm that for any of the following CRL DPs: http://www.icp.minefi.gouv.fr/igca.crl (1 entry) http://www.icp.minefi.gouv.fr/ac-racine.crl

Re: Exceptions to 1024-bit cert revocation requirement

2013-12-12 Thread Kathleen Wilson
On 12/12/13 2:11 AM, Jan Schejbal wrote: Roots can be removed by disabling the trust bits (i.e. a reasonably simple change). This should be done ASAP after the relevant date - shouldn't it have been included in the Gecko/Firefox 27 beta currently running? Can it still be included, or is it too

Re: OCSP Stapling support is in Firefox 26

2013-12-12 Thread Jan Schejbal
Am 2013-12-13 02:09, schrieb Kathleen Wilson: Firefox 26, released this week, has support for OCSP stapling in it. Awesome! Does this already include the Require OCSP for EV changes, or is that going to come in a later version? Kind regards, Jan -- Please avoid sending mails, use the group