Re: New requirement: certlint testing

2016-02-14 Thread Matt Palmer
On Fri, Feb 12, 2016 at 02:00:26AM -0800, rafa...@gmail.com wrote: > Regarding this point, how will be addressed the issue about > AdministrativeID (directoryName) in SAN of electronic offices? > > As it has been said, all Spanishs CAs are issuing certs in this way in > order to comply with all

Re: New requirement: certlint testing

2016-02-14 Thread Steve
While time isn't entropic and in its minutes and seconds there are more variable bits than the 20 required by policies, the main influences in a subordination process are air gap, limitations on the number of rounds, and lack of control of the plaintext. Subordination occurs with paper contracts

Re: New requirement: certlint testing

2016-02-14 Thread Jakob Bohm
On 12/02/2016 12:03, Medin, Steven wrote: There's no requestor control of validityNotBefore for an offline CA signing event, and certainly none with an online CA since the Playstation attack. There's limited control of toBeSigned: CAs will grab the asserted subject DN, public key, and toss the