Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-28 Thread Wayne Thayer via dev-security-policy
Piotr just filed an incident report on the misissuance that was reported on 18-January: https://bugzilla.mozilla.org/show_bug.cgi?id=1523186 The report discloses another misissuance that occurred during testing, resulting in a serverAuth certificate with a duration of over 5 years. On Sun, Jan

Re: misissued.com FYI

2019-01-28 Thread Eric Mill via dev-security-policy
Would you consider tossing the backup in a zip file in an S3 bucket or something, and sharing a link for the record here, for others finding this in the future? On Mon, Jan 28, 2019 at 10:05 AM Alex Gaynor via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hi All, > > For

misissued.com FYI

2019-01-28 Thread Alex Gaynor via dev-security-policy
Hi All, For anyone using https://misissued.com/ I wanted to provide a quick FYI about some database maintenance. The database was nearing its storage capacity limit, and so I deleted all certificates from it that had expired before 2019. The main consequence of this is that you can't use