Re: Incident report D-TRUST: syntax error in one tls certificate

2018-12-03 Thread Jakob Bohm via dev-security-policy
On 04/12/2018 05:38, Nick Lamb wrote: > On Tue, 4 Dec 2018 01:39:05 +0100 > Jakob Bohm via dev-security-policy > wrote: > >> A few clarifications below >> Interesting. What is that hole? > > I had assumed that you weren't aware that you could just use these > systems as designed. Your

Re: Incident report Certum CA: Corrupted certificates

2018-12-03 Thread Wojciech Trapczyński via dev-security-policy
Thank you. The answers to your questions below. On 04.12.2018 00:47, Jakob Bohm via dev-security-policy wrote: On 03/12/2018 12:06, Wojciech Trapczyński wrote: Please find our incident report below. This post links to https://bugzilla.mozilla.org/show_bug.cgi?id=1511459. --- 1. How your CA

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-12-03 Thread Nick Lamb via dev-security-policy
On Tue, 4 Dec 2018 01:39:05 +0100 Jakob Bohm via dev-security-policy wrote: > A few clarifications below > Interesting. What is that hole? I had assumed that you weren't aware that you could just use these systems as designed. Your follow-up clarifies that you believe doing this is unsafe. I

Re: Incident report D-TRUST: syntax error in one tls certificate

2018-12-03 Thread Jakob Bohm via dev-security-policy
A few clarifications below On 30/11/2018 10:48, Nick Lamb wrote: > On Wed, 28 Nov 2018 22:41:37 +0100 > Jakob Bohm via dev-security-policy > wrote: > >> I blame those standards for forcing every site to choose between two >> unfortunate risks, in this case either the risks prevented by those >>

Re: Incident report Certum CA: Corrupted certificates

2018-12-03 Thread Jakob Bohm via dev-security-policy
On 03/12/2018 12:06, Wojciech Trapczyński wrote: > Please find our incident report below. > > This post links to https://bugzilla.mozilla.org/show_bug.cgi?id=1511459. > > --- > > 1. How your CA first became aware of the problem (e.g. via a problem > report submitted to your Problem Reporting

Incident report Certum CA: Corrupted certificates

2018-12-03 Thread Wojciech Trapczyński via dev-security-policy
Please find our incident report below. This post links to https://bugzilla.mozilla.org/show_bug.cgi?id=1511459. --- 1. How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a