Re: TrustCor root inclusion request

2017-05-18 Thread Nick Lamb via dev-security-policy
On Thursday, 18 May 2017 04:23:17 UTC+1, Aaron Wu wrote: > - DV SSL Certificates - the domain name registrar must list the applicant as > part of the WHOIS record; or effective control of the domain shall be > demonstrated by the applicant or communication satisfying BR 3.2.2.4 shall be >

Re: DRAFT: Notice to CAs about CCADB changes May 19-21

2017-05-18 Thread Kathleen Wilson via dev-security-policy
On Thursday, May 18, 2017 at 10:08:32 AM UTC-7, Kathleen Wilson wrote: > All, > > Below is the draft email that I plan to send later today, after we have final > confirmation from Salesforce regarding these proposed changes. > We received confirmation from Salesforce that these changes to the

DRAFT: Notice to CAs about CCADB changes May 19-21

2017-05-18 Thread Kathleen Wilson via dev-security-policy
All, Below is the draft email that I plan to send later today, after we have final confirmation from Salesforce regarding these proposed changes. I will appreciate your feedback on this. Thanks, Kathleen Subject: Common CA Database (CCADB) changes May 19-21, 2017 Dear Certification

RE: Email sub-CAs

2017-05-18 Thread Doug Beattie via dev-security-policy
Hi Gerv, I'm still looking for audit guidance on subordinate CAs that have EKU of Server auth and/or Secure Mail along with name constraints. Do these need to be audited? I'm looking at this: https://github.com/mozilla/pkipolicy/blob/master/rootstore/policy.md Section 1.1, item #2 implies