RE: Incidents involving the CA WoSign

2016-09-14 Thread Richard Wang
Today or tomorrow. Now it is almost finished that someone is correcting my English. :-) Regards, Richard -Original Message- From: dev-security-policy [mailto:dev-security-policy-bounces+richard=wosign@lists.mozilla.org] On Behalf Of Peter Bowen Sent: Thursday, September 15, 2016 1

Re: Incidents involving the CA WoSign

2016-09-14 Thread Peter Bowen
On Sat, Sep 10, 2016 at 6:43 PM, Richard Wang wrote: > We will publish a more comprehensive report in the next several days that > will attempt to cover most / all issues. > Thanks for your patience. Richard, Thank you in advance for working on a comprehensive report. I appreciate it takes sig

Re: Compromised certificate that the owner didn't wish to revoke (signed by GeoTrust)

2016-09-14 Thread Jakob Bohm
On 14/09/2016 16:11, Kyle Hamilton wrote: On 9/12/2016 20:20, Jakob Bohm wrote: On 13/09/2016 03:03, Kyle Hamilton wrote: I would prefer not to see a securelogin-.arubanetworks.com name, because such makes it look like Aruba Networks is operating the captive portal. If (for whate

Re: Compromised certificate that the owner didn't wish to revoke (signed by GeoTrust)

2016-09-14 Thread Kyle Hamilton
On 9/12/2016 20:20, Jakob Bohm wrote: > On 13/09/2016 03:03, Kyle Hamilton wrote: >> I would prefer not to see a securelogin-.arubanetworks.com >> name, because such makes it look like Aruba Networks is operating the >> captive portal. If (for whatever reason) the system is compromis