Re: Sectigo to Be Acquired by GI Partners

2020-10-12 Thread Matt Palmer via dev-security-policy
On Fri, Oct 09, 2020 at 06:33:22AM -0700, Tim Callan via dev-security-policy wrote: > We anticipate no meaningful changes required to policies, operations, or > personnel. [...] > In this case the required changes are virtually nothing. These statements concern me somewhat, as reasonable

Re: Sectigo to Be Acquired by GI Partners

2020-10-12 Thread Jakob Bohm via dev-security-policy
Hi Rob, The e-mail you quote below seems to be inadvertently "confirming" some suspicions that someone else posed as questions. I think the group as a whole would love to have actual specific answers to those original questions. Remember to always add an extra layer of ">" indents for each

Re: PEM of root certs in Mozilla's root store

2020-10-12 Thread Kathleen Wilson via dev-security-policy
On 10/7/20 1:09 PM, Jakob Bohm wrote: Please note that at least the first CSV download is not really a CSV file, as there are line feeds within each "PEM" value, and only one column.  It would probably be more useful as a simple concatenated PEM file, as used by various software packages as a

Re: Verifying Auditor Qualifications

2020-10-12 Thread Kathleen Wilson via dev-security-policy
On 10/11/20 11:06 PM, Nikolaos Soumelidis wrote: Dear Kathleen, We have been informed by ACCREDIA that the accreditation pages have now been updated to include ETSI EN 319 403. This removes any ambiguity. URLs remain the same; for example, QMSCERT's accreditation:

Re: Sectigo to Be Acquired by GI Partners

2020-10-12 Thread Tim Callan via dev-security-policy
On Saturday, October 3, 2020 at 5:16:41 PM UTC-4, Ryan Sleevi wrote: > 1. Is it expected that there will be similar system and/or infrastructure > migrations as part of this? Sectigo's foresight of "no effect on its > operations" leaves it a bit ambiguous whether this is meant as "practical" >

Re: Sectigo to Be Acquired by GI Partners

2020-10-12 Thread Rob Stradling via dev-security-policy
Hi Ryan. Tim Callan posted a reply to your questions last week, but his message has not yet appeared on the list. Is it stuck in a moderation queue? From: dev-security-policy on behalf of Ryan Sleevi via dev-security-policy Sent: 03 October 2020 22:16 To:

RE: Verifying Auditor Qualifications

2020-10-12 Thread Nikolaos Soumelidis via dev-security-policy
Dear Kathleen, We have been informed by ACCREDIA that the accreditation pages have now been updated to include ETSI EN 319 403. This removes any ambiguity. URLs remain the same; for example, QMSCERT's accreditation: