Re: ComSign Root Renewal Request

2016-01-29 Thread Peter Bowen
Peter, I obviously do not represent ComSign, but several of the items in your list are not really specific to the CPS and instead are more comments on the Mozilla policies. On Fri, Jan 29, 2016 at 4:24 PM, Peter Kurrasch wrote: > * There is a BR from CABF that covers code

Re: SHA1 certs issued this year chaining to included roots

2016-01-29 Thread Richard Barnes
On Fri, Jan 29, 2016 at 4:43 PM, Kathleen Wilson wrote: > On 1/25/16 12:22 AM, Charles Reiss wrote: > >> On 01/19/16 01:49, Charles Reiss wrote: >> >>> Via censys.io, I found a couple SHA-1 certs with notBefore dates from >>> this year >>> which chain to root CAs in

Re: ComSign Root Renewal Request

2016-01-29 Thread Peter Kurrasch
I've reviewed the ComSign CPS and while it has a lot of legal language in it, it lacks a certain legal and technical precision that is needed in this case. For example, there is frequent use of the term

Re: SHA1 certs issued this year chaining to included roots

2016-01-29 Thread Kathleen Wilson
On 1/25/16 12:22 AM, Charles Reiss wrote: On 01/19/16 01:49, Charles Reiss wrote: Via censys.io, I found a couple SHA-1 certs with notBefore dates from this year which chain to root CAs in Mozilla's program: [snip] And here are a couple more, from different subCAs: -