RE: On the value of EV

2017-12-20 Thread Tim Hollebeek via dev-security-policy
Wayne, Thanks for updating us on Mozilla's thinking on this issue. On behalf of the CA/Browser forum Validation Working Group, I would like to thank everyone for their time and contributions. We will be going over everyone's points and take them all into consideration as we look into what

Re: ComSign Root Renewal Request

2017-12-20 Thread Wayne Thayer via dev-security-policy
Doug, I am not aware of any requirement for CAs to detect or prevent homograph spoofing in the names contained in certificates they issue. Mozilla's position is that this is something best handled by registries/registrars just as stated in the CPS you quoted. In the case of the ComSign CPS, my

Mozilla CA Team availability

2017-12-20 Thread Gervase Markham via dev-security-policy
The Mozilla CA team will have limited availability over the Christmas and New Year period, and so you should not expect us to engage substantively in complex debates, make controversial decisions, or otherwise act as if we were functioning at full strength :-) We hope that normal service will be