Re: CA scope transparency (was Re: Name-constraining government CAs, or not)

2015-06-04 Thread Matt Palmer
Hi Richard, On Thu, Jun 04, 2015 at 02:44:00PM -0400, Richard Barnes wrote: The thing that was driving my earlier proposal with regard to name constraints was a feeling of imbalance. With every CA we add to our program we add risk for every site on the web. That cost is supposed to be

CA scope transparency (was Re: Name-constraining government CAs, or not)

2015-06-04 Thread Richard Barnes
I'd like to try to up-level some of the discussions we're having about name constraints, to see if we can find some higher-level consensus. The thing that was driving my earlier proposal with regard to name constraints was a feeling of imbalance. With every CA we add to our program we add risk

WoSign Root Renewal Request

2015-06-04 Thread Kathleen Wilson
WoSign has applied to include the Certification Authority of WoSign G2 and CA WoSign ECC Root root certificates, turn on all three trust bits for both roots, and enable EV treatment for both roots. WoSign's previous root certificates were included via Bugzilla Bug #851435. WoSign issues