RE: Mozilla Policy Requirements CA Incidents

2019-10-15 Thread Jeremy Rowley via dev-security-policy
I like this approach. You could either add a page in the policy document or include the information in the management assertion letter (or auditor letter) that gives information about the auditor’s credentials and background. I also like the idea of summary on what the auditor followed up on

Re: Audit Letter Validation (ALV) on intermediate certs in CCADB

2019-10-15 Thread Kathleen Wilson via dev-security-policy
On 10/8/19 12:50 PM, Kathleen Wilson wrote: CAs, There is now an "Audit Letter Validation (ALV)" button on intermediate certificate records in the CCADB. There is also a new task list item on your home page. In the summary section you will see a line item like the following.    

Re: Audit Reminder Email Summary

2019-10-15 Thread Kathleen Wilson via dev-security-policy
Forwarded Message Subject: Summary of October 2019 Audit Reminder Emails Date: Tue, 15 Oct 2019 19:00:07 + (GMT) Mozilla: Audit Reminder CA Owner: E-Tugra Root Certificates: E-Tugra Certification Authority Standard Audit:

Re: Request to Include 4 Microsoft Root CAs

2019-10-15 Thread Ryan Sleevi via dev-security-policy
(Replying for the correct address this time) On Fri, Aug 16, 2019 at 4:28 PM Jason via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hi All, > > This is Jason from the Microsoft PKI Services team. I’d like to add some > context to the note about the certs issued from the