Re: Disclosure and CP/CPS for Cross-Signed Roots

2019-07-26 Thread Brenda Bernal via dev-security-policy
We are curious why our cross-roots are showing up on the list? Can you share the logic on why these are appearing on the report? As far as our reviews are concerned, we see that all of these cross-roots are properly disclosed and have covering audits. We also see that you have listed CAs where

Re: Entrust Root Certification Authority - G4 Inclusion Request

2019-07-26 Thread Bruce via dev-security-policy
On Friday, July 26, 2019 at 1:45:06 PM UTC-4, Ryan Sleevi wrote: > (In a personal capacity, as normally noted but making sure to extra-note it > here) > > Hi Wayne, > > It wasn't clear to me from the inclusion request, did Entrust give a reason > for the requested addition? For example, do they

Re: Entrust Root Certification Authority - G4 Inclusion Request

2019-07-26 Thread Ryan Sleevi via dev-security-policy
(In a personal capacity, as normally noted but making sure to extra-note it here) Hi Wayne, It wasn't clear to me from the inclusion request, did Entrust give a reason for the requested addition? For example, do they plan to stop issuing from one of the included roots and have it removed? In

Entrust Root Certification Authority - G4 Inclusion Request

2019-07-26 Thread Wayne Thayer via dev-security-policy
This request is to include the Entrust Root Certification Authority - G4 as documented in the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1480510 * BR Self Assessment is here: https://bug1480510.bmoattachments.org/attachment.cgi?id=8997108 * Summary of Information Gathered and

Re: Nation State MITM CA's ?

2019-07-26 Thread sedric2008--- via dev-security-policy
четверг, 7 января 2016 г., 4:08:10 UTC+5 пользователь Paul Wouters написал: > As was in the news before, Kazakhstan has issued a national MITM > Certificate Agency. > > Is there a policy on what to do with these? While they are not trusted, > would it be useful to explicitely blacklist these, as

Re: Nation State MITM CA's ?

2019-07-26 Thread bayden--- via dev-security-policy
On Friday, July 19, 2019 at 10:53:16 AM UTC-5, Matthew Hardeman wrote: > While possible, that seems unlikely. Corporates are, in general, not > trying to hide when this is being done. > > In fact, there are lots of good legal liability reasons why they should > want their users to be constantly