Re: PEM of root certs in Mozilla's root store

2020-10-06 Thread Ryan Sleevi via dev-security-policy
It seems like there should be a link to https://wiki.mozilla.org/CA/FAQ#Can_I_use_Mozilla.27s_set_of_CA_certificates.3F there I realize there’s a tension between making this easily consumable, and the fact that “easily consumed” doesn’t and can’t relieve an organization of having to be

Re: Let's Encrypt: 302 total OCSP responses served beyond acceptable timelines

2020-10-06 Thread Jacob Hoffman-Andrews via dev-security-policy
On Sat, Sep 26, 2020 at 9:09 PM Nick Lamb via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Let's Encrypt provides a community mutual assistance site (with > contributions from staff) on which a large volume of messages are > posted each day. > >

PEM of root certs in Mozilla's root store

2020-10-06 Thread Kathleen Wilson via dev-security-policy
All, I've been asked to publish Mozilla's root store in a way that is easy to consume by downstreams, so I have added the following to https://wiki.mozilla.org/CA/Included_Certificates CCADB Data Usage Terms PEM of Root

Re: Policy 2.7.1 Issues to be Considered

2020-10-06 Thread Ben Wilson via dev-security-policy
Corey, We will add this to the 2.7.1 batch of proposed changes. I've started discussion of Issue 147, so we can discuss it there, or I can create a separate email thread for it. On Fri, Oct 2, 2020 at 5:16 AM Corey Bonnell wrote: > Including https://github.com/mozilla/pkipolicy/issues/152 would

MRSP Issue #147 - Require EV audits for certificates capable of issuing EV certificates

2020-10-06 Thread Ben Wilson via dev-security-policy
#147 - Require EV audits for certificates capable of issuing EV certificates – Clarify that EV audits are required for all intermediate certificates that are technically capable of issuing EV certificates, even when not currently issuing EV

MRSP Issue #139: Audits required even if not issuing

2020-10-06 Thread Ben Wilson via dev-security-policy
Here is the first issue for discussion here on the m.d.s.p. list relative to the next version of the Mozilla Root Store Policy (v.2.7.1). #139 - Audits are required even if no longer issuing - Clarify that audits are required until the CA

Re: Policy 2.7.1 Issues to be Considered

2020-10-06 Thread Ben Wilson via dev-security-policy
Doug, I don't have any preconceived notions. I was hoping that by discussing the implementation issues for each issue we could determine appropriate timeframes. Ben On Tue, Oct 6, 2020 at 12:19 PM Doug Beattie wrote: > Ben, > > When, approximately, do you think this proposed updates would

RE: Policy 2.7.1 Issues to be Considered

2020-10-06 Thread Doug Beattie via dev-security-policy
Ben, When, approximately, do you think this proposed updates would become effective, and specifically this item: https://github.com/mozilla/pkipolicy/issues/206 Doug -Original Message- From: dev-security-policy On Behalf Of Ben Wilson via dev-security-policy Sent: Thursday,

Re: Audit Reminders for Intermediate Certs

2020-10-06 Thread Kathleen Wilson via dev-security-policy
Forwarded Message Subject: Summary of October 2020 Outdated Audit Statements for Intermediate Certs Date: Tue, 6 Oct 2020 14:00:25 + (GMT) CA Owner: Government of The Netherlands, PKIoverheid (Logius) - Certificate Name: QuoVadis PKIoverheid Organisatie Server CA - G3