Re: Policy 2.7 Proposal: Forbid Delegation of Email Validation for S/MIME Certificates

2019-05-23 Thread Kathleen Wilson via dev-security-policy
On 5/13/19 10:24 AM, Wayne Thayer wrote: The BRs forbid delegation of domain and IP address validation to third parties. However, the BRs don't forbid delegation of email address validation nor do they apply to S/MIME certificates. Delegation of email address validation is already addressed by

Changes to ccadb.org site and report links

2019-05-23 Thread Kathleen Wilson via dev-security-policy
All, We've made the following changes to the ccadb.org site. 1) The general links providing data for all CAs and certs in the CCADB have been updated from "mozilla" to "ccadb". In particular the first three links in the General section on the Resources tab have been updated.

RE: GlobalSign misissuance: 4 certificates with invalid CN

2019-05-23 Thread Doug Beattie via dev-security-policy
Hi Nick, I updated our Mozilla ticket this this info and I wanted to also supply it here because it answers your questions also https://bugzilla.mozilla.org/show_bug.cgi?id=1552586 Here is an update to this incident: 5/20: After further analysis of the issue, it was determined that the

Re: Certinomis Issues

2019-05-23 Thread Kathleen Wilson via dev-security-policy
On 5/16/19 4:39 PM, Wayne Thayer wrote: On Thu, May 16, 2019 at 4:23 PM Wayne Thayer wrote: I will soon file a bug requesting removal of the “Certinomis - Root CA” from NSS. This is https://bugzilla.mozilla.org/show_bug.cgi?id=1552374 Thank you to Wayne and all of you who have