Re: Proposed change to CA contact policy

2017-10-11 Thread Gervase Markham via dev-security-policy
On 09/10/17 18:04, Matthew Hardeman wrote: > Echoing Mr. Lamb's concern, I would think that defining two > "important notice role/mailing list recipient addresses" and always > sending important notices to both. This would allow for a mailing > list on CA internal infrastructure as well as one on

Re: DigiCert-Symantec Announcement

2017-10-11 Thread Peter Kurrasch via dev-security-policy
Clearly there has to be a way for key compromises to be remedied. If I've been following this pinning discussion correctly it seems unavoidable that we will have cases requiring certs to be issued on the soon-to-b

Re: Certigna Root Renewal Request

2017-10-11 Thread asymmetric--- via dev-security-policy
Certigna BR Review Adding onto Nick’s suggestions, here are some notes from my review of this application request: Noteworthy good aspects: - The supplied PKI diagrams are clear and useful for understanding the hierarchy and purpose of each CA. Thank you for providing this. - CPs are in RFC 3