AC Camerfirma's undisclosed itermediate certificates incident report

2018-08-02 Thread Juan Angel Martin via dev-security-policy
Hello, 1) How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a Bugzilla bug, or internal self-audit), and the time and date. We receive a communication via Buzilla from Wayne Tha

Re: AC Camerfirma's undisclosed itermediate certificates incident report

2018-08-02 Thread Kurt Roeckx via dev-security-policy
On Thu, Aug 02, 2018 at 06:19:42AM -0700, Juan Angel Martin via dev-security-policy wrote: > > 6) Explanation about how and why the mistakes were made or bugs introduced, > and how they avoided detection until now. > > The procedure established to publish the CAs into CCADB wasn't correct caus

localhost.megasyncloopback.mega.nz private key in client

2018-08-02 Thread summern1538--- via dev-security-policy
Hello everyone, I'm not sure where to report this issue, this is my fist cert issue report. I tried to report it to GeoTrust, but they don't know about this domain. Replay from GeoTrust > Good day, > > Thank you very much for the friendly request. > > Unfortunately I was not able to find any

RE: localhost.megasyncloopback.mega.nz private key in client

2018-08-02 Thread Ben Wilson via dev-security-policy
Thank you Norbert. We will look into this. I'm cc'ing rev...@digicert.com to follow up. -Original Message- From: dev-security-policy On Behalf Of summern1538--- via dev-security-policy Sent: Thursday, August 2, 2018 4:06 AM To: mozilla-dev-security-pol...@lists.mozilla.org Subject: loca

RE: localhost.megasyncloopback.mega.nz private key in client

2018-08-02 Thread Ben Wilson via dev-security-policy
Norbert, I've tried to verify this with and without spaces in the msg.asc below. I get "Signature Verification Failure". Please contact me off-list to provide me clearer information related to your proof of private key possession. Thanks, Ben Wilson -Original Message- From: dev-security-

Re: Certigna Root Renewal Request

2018-08-02 Thread asymmetric--- via dev-security-policy
Hello, Based on the updated documentation, I've compiled the following questions for clarification: CPS Section 1.4.2 states "Unless stated otherwise, in this document, “RA” covers the Registration Authority and Delegate Registration Authorities." CPS Section 3.2 calls out DRAs ab

Re: localhost.megasyncloopback.mega.nz private key in client

2018-08-02 Thread summern1538--- via dev-security-policy
Hello Ben, Thanks for your fast response and help. After a bit research I also found the source with the key: https://github.com/meganz/MEGAsync/blob/master/src/MEGASync/control/Preferences.cpp As it is public I think it should not be problem to post it here. Best Regards Norbert __