Re: WoSign: updated report and discussion

2016-10-09 Thread 谭晓生
I also said that the official website, ordering system, certificate management system are different and independent, which is the major cause of the bugs from technical perspective, that’s why Wosign suffered the incidents of bugs but StartCom haven’t. The validation team, customer care team

Re: Include Symantec-brand Class 1 and Class 2 Root Certs

2016-10-09 Thread Matt Palmer
On Fri, Oct 07, 2016 at 09:05:37PM +0200, Jakob Bohm wrote: > On 07/10/2016 19:14, Kathleen Wilson wrote: > >On Thursday, October 6, 2016 at 4:27:10 PM UTC-7, Peter Bowen wrote: > >>It isn't > >>clear to me that the subordinate CA disclosure rule even applies to > >>e-mail only roots. > > > >We

Re: WoSign: updated report and discussion

2016-10-09 Thread Percy
Tan said, for StartCom and WoSign’s infrastructure, the PKI servers were/are shared, the CRL/OCSP, TSA code were cloned and the StartCom and WoSign shared the software development team. Also some management team are shared I assume since Richard Wang approved Tyro's backdated cert from

Re: WoSign: updated report and discussion

2016-10-09 Thread Matt Palmer
On Sun, Oct 09, 2016 at 08:47:59AM -0700, Peter Bowen wrote: > I think the proposal from 360 to operate WoSign and StartCom as > separate subsidiaries is interesting and something that is well worth > reviewing if/when they apply to rejoin the program. However that does > not change the past.

Re: WoSign and StartCom: next steps

2016-10-09 Thread Eddy Nigg
On 10/07/2016 12:38 PM, Gervase Markham wrote: I am a little surprised it hasn't appeared by now. We did not agree a specific deadline, but my impression was that it would appear in a few days, which I mentally interpreted as "by the end of the week". Today is Friday, so there is still time for