Re: How to use Cross Certificates to support Root rollover

2019-08-05 Thread Ryan Sleevi via dev-security-policy
Top-posting, to try and reset the legibility on things. Regarding the definition for "cross-certified intermediate": Both scenarios you describe are cross-certificates. This is perhaps clearer with RFC 4158's treatment of it (for which the BR language was borrowed from), and may not be as

RE: How to use Cross Certificates to support Root rollover

2019-08-05 Thread Doug Beattie via dev-security-policy
Ryan, Note: I changed the name of the thread because this is a great discussion about root roll-over and isn’t really related to the Entrust Root inclusion request. In theory Cross certificates are simple, but I’ve found that in practice they are difficult to manage and use.

Re: How to use Cross Certificates to support Root rollover

2019-08-05 Thread Ryan Sleevi via dev-security-policy
Hi Doug, Unfortunately, it looks like your approach to replying inline completely destroyed the formatting. I'm unable to follow or determine your responses, based on your mail client. You can see both as rich text [1] and plain text [2] that your formatting makes your responses illegible, to

Re: How to use Cross Certificates to support Root rollover

2019-08-05 Thread Jakob Bohm via dev-security-policy
One note: As a company that actively supports users with old operating systems and OS-provided root stores, we have been deliberately including your R1-R3 cross, and are battling problems with a few really old platforms that plain don't support any certs currently available. This isn't just

How to use Cross Certificates to support Root rollover

2019-08-05 Thread Doug Beattie via dev-security-policy
Ryan, Note: I changed the name of the thread because this is a great discussion about root roll-over and isn’t really related to the Entrust Root inclusion request. In theory Cross certificates are simple, but I’ve found that in practice they are difficult to manage and use. First,