RE: Certificates with less than 64 bits of entropy

2017-08-19 Thread Stephen Davidson via dev-security-policy
Ah, my apologies. https://bugzilla.mozilla.org/attachment.cgi?id=8898848 Regards, Stephen From: dev-security-policy [dev-security-policy-bounces+s.davidson=quovadisglobal@lists.mozilla.org] on behalf of Eric Mill via dev-security-policy

Re: Certificates with less than 64 bits of entropy

2017-08-19 Thread Eric Mill via dev-security-policy
On Fri, Aug 18, 2017 at 12:04 PM, Stephen Davidson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > > 4) The list of affected certificates is attached in spreadsheet > form; they will be uploaded to CT as well. You will note that the number > has declined – Siemens'

Re: Expired Certificates Listed by Certificate Manager

2017-08-19 Thread userwithuid via dev-security-policy
On Tuesday, August 15, 2017 at 12:32:01 PM UTC, Gervase Markham wrote: > OneCRL does not obsolete certdata.txt-based distrust because not > everyone checks OneCRL. While we can't add every cert in OneCRL to > certdata.txt, we should add the big dis-trusts to it. Do you think > there's anything