Re: Incident Report - Misissuance of one certificate without DNS CAA authorization (Certigna)

2018-10-03 Thread Matt Palmer via dev-security-policy
On Wed, Oct 03, 2018 at 09:31:08AM -0700, Wayne Thayer wrote: > On Mon, Oct 1, 2018 at 4:49 AM Matt Palmer via dev-security-policy < > dev-security-policy@lists.mozilla.org> wrote: > > Thank you for this clear statement of your validation interface design. > > Unfortunately, this sounds like a

Re: Incident Report - Misissuance of one certificate without DNS CAA authorization (Certigna)

2018-10-03 Thread Wayne Thayer via dev-security-policy
Hi Matt, I appreciate your interest in getting to the root causes of this issue, and the polite and professional manner in which you are asking questions. However, I am concerned that this line of questioning seem to have reached the limits of Certigna's analysis capabilities, and is thus

DoS attack without consequences to Firmaprofesional

2018-10-03 Thread Chema Lopez via dev-security-policy
Good afternoon, I send this email to inform that on Saturday, October 29th, between 12:00 and 19:45 (CEST) approximately, the services of Firmaprofesional were subject to a denial of service attack (DoS), which, thanks to the company's security systems did not have a notable impact. There were