Re: Incident Reporting Guidance

2019-12-11 Thread Wayne Thayer via dev-security-policy
While thinking about different ways to solve the problem of disclosing missed revocation deadlines, we devised a solution for searching and reporting on delayed revocations separately from other incidents. We've begun to add a new Bugzilla "whiteboard" label to delayed revocation incident bugs. We

Root Store Policy 2.7 Published

2019-12-11 Thread Wayne Thayer via dev-security-policy
The new version of the Mozilla Root Store Policy has been published [1]. This version goes into effect on January 1, 2020. The prior version that is in effect for the rest of 2019 is linked from the wiki [2]. I have also just posted an announcement [3] on the Mozilla Security Blog. We will be