Re: TLS certificates for ECIES keys

2020-11-02 Thread Devon O'Brien via dev-security-policy
Hi Jacob, I’m chiming in in my official capacity as a member of Chrome’s root program and its Certificate Transparency lead. Over the past several years, the narrowing of scope for both the web PKI and CT has been highly intentional. Great efforts have been made to ensure that use cases

Re: Policy 2.7.1: MRSP Issue #186: Requirement to Disclose Self-signed Certificates

2020-11-02 Thread Corey Bonnell via dev-security-policy
As an alternate proposal, I suggest replacing the third paragraph of section 5.3, which currently reads: "These requirements include all cross-certificates which chain to a certificate that is included in Mozilla’s CA Certificate Program." with: "A certificate is considered to directly or

Re: Policy 2.7.1: MRSP Issue #186: Requirement to Disclose Self-signed Certificates

2020-11-02 Thread Jakob Bohm via dev-security-policy
On 2020-10-30 18:45, Ryan Sleevi wrote: On Fri, Oct 30, 2020 at 12:38 PM Jakob Bohm via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: On 2020-10-30 16:29, Rob Stradling wrote: Perhaps add: "And also include any other certificates sharing the same private/public key pairs