CCADB experiencing access issues

2017-11-02 Thread Kathleen Wilson via dev-security-policy
All, The CCADB is currently experiencing problems that Salesforce is working to resolve. When you try to access a record, you will get an error that says: "URL No Longer Exists" We have added a message to the home page: * * * CCADB database is experiencing access issues. We are working to re

Re: Bugzilla/wiki integration broken

2017-11-02 Thread Kathleen Wilson via dev-security-policy
On 10/31/17 10:36 AM, Kathleen Wilson wrote: On Monday, October 30, 2017 at 5:17:38 PM UTC-7, Kathleen Wilson wrote: On Saturday, October 28, 2017 at 5:07:51 PM UTC-7, Kathleen Wilson wrote: All, Mozilla's Bugzilla system was updated a couple of days ago, and now the Bugzilla/wiki integration

Re: Incident report: Certificates with error in subject: postalCode

2017-11-02 Thread Jakob Bohm via dev-security-policy
On 02/11/2017 13:27, Nick Lamb wrote: My understanding is that postal codes written in this form are understood (even if not always specifically permitted) by many postal authorities and so this deviation would not be likely to impact deliverability of a snail mail letter sent (for whatever re

Re: Estonia e-residency instructing users not to update Firefox (on Mac)

2017-11-02 Thread Gervase Markham via dev-security-policy
On 02/11/17 10:39, Henri Sivonen wrote: > A Medium post claiming[1] to represent Estonia e-residency > https://medium.com/e-residency-blog/estonia-is-enhancing-the-security-of-its-digital-identities-361b9a3c9c52 > instructs Mac users not to update Firefox from December 15 2017 onwards. The policy

Incident report: Certificates with error in subject: postalCode

2017-11-02 Thread Nick Lamb via dev-security-policy
My understanding is that postal codes written in this form are understood (even if not always specifically permitted) by many postal authorities and so this deviation would not be likely to impact deliverability of a snail mail letter sent (for whatever reason) to the address shown in the certif

Estonia e-residency instructing users not to update Firefox (on Mac)

2017-11-02 Thread Henri Sivonen via dev-security-policy
(Not sure if this is the right mailing list, but while I'm not sure how exactly the PKI operations of the government of Estonia are structured organizationally, on surface it looks like this is related to client cert activities of a CA that is Mozilla-trusted for server certs.) A Medium post claim

Re: StartCom inclusion request: next steps

2017-11-02 Thread Gervase Markham via dev-security-policy
Dear Inigo, On 14/09/17 09:49, Gervase Markham wrote: > The Mozilla CA Certificates team has been considering what the > appropriate next steps are for the inclusion request from the CA > "StartCom".[0] As readers will know, this CA has previously been removed > from trust[1], and so a re-applicat

AW: Swiss Government root inclusion request

2017-11-02 Thread Michael von Niederhäusern via dev-security-policy
Hi Julien The link got cut by a linefeed in the original post: http://www.pki.admin.ch/public/25-01-2017-BIT-ZertES-Certification-Confirmation-2017_Final.pdf The annual audits are updated for the actual period. The certification confirmation is for 2017 where the audits were still performed E

Re: Swiss Government root inclusion request

2017-11-02 Thread Julien Cristau via dev-security-policy
On Thu, Nov 2, 2017 at 9:29 AM, Aaron Wu via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > > * Audit: Annual audits are performed by KPMG according to the ETSI TS 102 > 042 for CA and BR audit criteria. > http://www.pki.admin.ch/public/25-01-2017-BIT-ZertES- > Certification

Swiss Government root inclusion request

2017-11-02 Thread Aaron Wu via dev-security-policy
This request from the Swiss Government is to include the “Swiss Government Root CA III” root certificate, turn on the Websites trust bit, and enable EV treatment. The request is documented in the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=435026 BR Self Assessment is here: htt