Re: Incident report D-TRUST: syntax error in one tls certificate

2018-11-26 Thread Ryan Sleevi via dev-security-policy
On Mon, Nov 26, 2018 at 12:12 PM Jakob Bohm via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > 1. Having a spare certificate ready (if done with proper security, e.g. >a separate key) from a different CA may unfortunately conflict with >badly thought out parts of

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-11-26 Thread Ryan Sleevi via dev-security-policy
On Mon, Nov 26, 2018 at 10:31 AM Nick Lamb via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > CA/B is the right place for CAs to make the case for a general rule about > giving themselves more time to handle technical non-compliances whose > correct resolution will annoy

Late Certinomis Audit (Was: Audit Reminder Email Summary)

2018-11-26 Thread Wayne Thayer via dev-security-policy
Update: I heard back from Certinomis quickly. They provided the following attestation statement from LSTI dated 23-November on the same day. The audit was conducted back in July, so we still need an explanation from Certinomis of why it took LSTI so long to provide the report.

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-11-26 Thread Jakob Bohm via dev-security-policy
On 23/11/2018 16:24, Enrico Entschew wrote: > This post links to https://bugzilla.mozilla.org/show_bug.cgi?id=1509512 > > syntax error in one tls certificate > > 1. How your CA first became aware of the problem (e.g. via a problem report > submitted to your Problem Reporting Mechanism, a

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-11-26 Thread Jakob Bohm via dev-security-policy
On 26/11/2018 16:31, Nick Lamb wrote: In common with others who've responded to this report I am very skeptical about the contrast between the supposed importance of this customer's systems versus their, frankly, lackadaisical technical response. This might all seem harmless but it ends up as

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-11-26 Thread Nick Lamb via dev-security-policy
In common with others who've responded to this report I am very skeptical about the contrast between the supposed importance of this customer's systems versus their, frankly, lackadaisical technical response.This might all seem harmless but it ends up as "the boy who cried wolf". If you relay

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-11-26 Thread Gijs Kruitbosch via dev-security-policy
(for the avoidance of doubt: posting in a personal capacity) On 23/11/2018 15:24, Enrico Entschew wrote: Timeline: 2018-11-12, 10:30 UTC Customer was contacted the first time. Customer runs an international critical trade platform for emissions. Immediate revocation of the certificate would