Re: About upcoming limits on trusted certificates

2020-03-12 Thread Julien Cristau via dev-security-policy
Hi Kathleen, all, Is there a reason domain validation information needs to be reused for more than, say, 30 days? For the manual parts of identity validation I understand you don't want to repeat the process too often, but domain validation can be entirely automated so it doesn't seem like long r

Re: 2020.02.29 Let's Encrypt CAA Rechecking Bug

2020-03-05 Thread Julien Cristau via dev-security-policy
I believe that's what https://bugzilla.mozilla.org/show_bug.cgi?id=1619179 is about. Cheers, Julien On Thu, Mar 5, 2020 at 2:09 PM Malcolm Doody via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Tuesday, 3 March 2020 15:37:00 UTC, Jacob Hoffman-Andrews wrote: > > We'v

Re: DigiCert validation issue

2019-06-05 Thread Julien Cristau via dev-security-policy
For those following along at home the incident report with details is in bugzilla: https://bugzilla.mozilla.org/show_bug.cgi?id=1556948 Cheers, Julien On Wed, Jun 5, 2019 at 8:17 AM Jeremy Rowley via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > I just posted this inciden

Re: ComSign Root Renewal Request

2018-02-05 Thread Julien Cristau via dev-security-policy
Re Section 3.4, you seem to assume the domain holder is a ComSign subscriber. In case of misissuance, that may not be true. Cheers, Julien On Mon, Feb 5, 2018 at 4:23 PM, YairE via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hi, thank you for pointing the above > Here

Re: Swiss Government root inclusion request

2017-11-02 Thread Julien Cristau via dev-security-policy
On Thu, Nov 2, 2017 at 9:29 AM, Aaron Wu via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > > * Audit: Annual audits are performed by KPMG according to the ETSI TS 102 > 042 for CA and BR audit criteria. > http://www.pki.admin.ch/public/25-01-2017-BIT-ZertES- > Certification