RE: Policy 2.7 Proposal: Clarify Section 5.1 ECDSA Curve-Hash Requirements

2019-05-24 Thread Doug Beattie via dev-security-policy
Wayne recommended that we open up a Mozilla incident ticket to track the 8 GlobalSign certificates of that do not contain the required null a parameter and thus violate the requirements of https://tools.ietf.org/html/rfc3279#section-2.3.1. https://bugzilla.mozilla.org/show_bug.cgi?id=1554259

Re: Policy 2.7 Proposal: Clarify Section 5.1 ECDSA Curve-Hash Requirements

2019-05-24 Thread Ryan Sleevi via dev-security-policy
On Wed, May 22, 2019 at 7:43 PM Brian Smith wrote: > Ryan Sleevi wrote: > >> >> >>> It would be easier to understand if this is true if the proposed text >>> cited the RFCs, like RFC 4055, that actually impose the requirements that >>> result in the given encodings. >>> >> >> Could you clarify,