Re: CFCA certificate with invalid domain

2019-03-25 Thread jonathansshn--- via dev-security-policy
在 2019年2月27日星期三 UTC+8下午11:28:00,michel.le...@gmail.com写道: > Hello, > > I noticed this certificate > https://crt.sh/?id=1231965201&opt=cablint,x509lint,zlint that has an invalid > domain `mail.xinhua08.con` in SANs. This looks like a typo and > `mail.xinhua08.com` is present in other certificate

Re: Something About CFCA (China Financial Certification Authority)

2016-10-31 Thread jonathansshn
在 2016年10月31日星期一 UTC+8上午11:28:04,Han Yuwei写道: > 在 2016年10月31日星期一 UTC+8上午9:35:04,jonath...@gmail.com写道: > > Please see 6.1.7 which describes these content. > > In version 3.2 I see that "证书最长期限(年)" (maxium validity period) about > "SSL服务器证书" (SSL Server Certficates) is 5. > > And I don't see any

Re: Something About CFCA (China Financial Certification Authority)

2016-10-30 Thread jonathansshn
Please see 6.1.7 which describes these content. ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy

Something About CFCA (China Financial Certification Authority)

2016-10-30 Thread jonathansshn
1, It’s not true. CFCA's RSA root that included in Mozilla is not able to issue sm2 certificate with sm3 hash. CFCA do have sm2 root that issue sm2 certificate but that root is not included in Mozilla or any other root store such as Apple, Microsoft or Google. And our CPS never indicate tha