Re: FW: StartCom inclusion request: next steps

2017-09-18 Thread Franck Leroy via dev-security-policy
Le lundi 18 septembre 2017 14:52:27 UTC+2, Ryan Sleevi a écrit : > On Mon, Sep 18, 2017 at 8:12 AM, Inigo Barreira <> > wrote: > Then they misissued a CA certificate and failed to disclose it, and we > should start an incident report into it. Hello In April 2017 the mozilla policy in force (v2.4)

Re: StartCom cross-signs disclosed by Certinomis

2017-08-07 Thread Franck Leroy via dev-security-policy
Hello I see many reactions that are not in line with the reality because you don’t have all the history on the subject. I’ll try to summarize. Approximately one year ago Inigo was CTO of Izenpe (CA of the Basque Country) and he left this company in order to join StartCom. Not long after he

Re: Certificates with invalidly long serial numbers

2017-08-07 Thread Franck Leroy via dev-security-policy
Hello I checked only one but I think they are all the same. The integer value of the serial number is 20 octets, but when encoded into DER a starting 00 may be necessary to mark the integer as a positive value : 0 1606: SEQUENCE { 4 1070: SEQUENCE { 83: [0] { 101:

Re: StartCom cross-signs disclosed by Certinomis

2017-08-03 Thread Franck Leroy via dev-security-policy
Hello, the 2 CA certificates signed by Certinomis has been retained till a full successful webtrust audit. On end of June the audit report form PwC was available but with still some minor issues. I asked StartCom to correct them. On July 14th the audit report and the policy were updated and