Re: Certinomis Issues

2019-05-28 Thread Ryan Sleevi via dev-security-policy
On Tue, May 28, 2019 at 1:03 PM Nick Lamb via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > If they shove an valid but nonsensical policy OID into a cert I don't know > what Mozilla policy about that would be, but certainly the browser and > common TLS clients will just

Re: Certinomis Issues

2019-05-28 Thread Nick Lamb via dev-security-policy
PSD2 is the Payment Services Directive 2 a Directive from the European Union. Directives aren't legislation per se, but tell the member states to write their own legislation to achieve some agreed outcome. Many things you think of as EU laws are actually Directives, as a citizen the broad effect

Re: Certinomis Issues

2019-05-28 Thread Hanno Böck via dev-security-policy
Hi, I just saw this on twitter: https://twitter.com/sam280/status/1133008218677022722 And later in the thread: https://twitter.com/sam280/status/1133112699385257985 The first tweet points out that Certinomis seems to use wrong OIDs in their certs (quote "Of course the first invalid #PSD2 #QWAC