Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-04 Thread Wayne Thayer via dev-security-policy
While a certain amount of latency in OCSP updates is expected when a certificate is first issued or revoked, KIR intended this to be a permanent "unknown" status for a revoked certificate. My conclusion from this discussion is that such a policy is not permitted, and the existing requirements are

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-03 Thread bif via dev-security-policy
On Friday, February 1, 2019 at 11:38:40 PM UTC+1, Kurt Roeckx wrote: > On Fri, Feb 01, 2019 at 03:02:17PM -0700, Wayne Thayer wrote: > > It was pointed out to me that the OCSP status of the misissued certificate > > that is valid for over 5 years is still "unknown" despite having been > > revoked

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-02 Thread Dimitris Zacharopoulos via dev-security-policy
kx via dev-security-policy > > Gesendet: Freitag, 1. Februar 2019 23:38 > > An: Wayne Thayer > > Cc: mozilla-dev-security-policy < > mozilla-dev-security-pol...@lists.mozilla.org> > > Betreff: Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations > (KIR) >

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-02 Thread Eric Mill via dev-security-policy
Berlin and > Munich, Germany; Commercial registries: Berlin Charlottenburg, HRB 12300, > Munich, HRB 6684; WEEE-Reg.-No. DE 23691322 > > > -Ursprüngliche Nachricht- > > Von: dev-security-policy > Im Auftrag von Kurt Roeckx via dev-security-policy > > Gesendet: Freitag,

AW: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-02 Thread Buschart, Rufus via dev-security-policy
m > Auftrag von Kurt Roeckx via dev-security-policy > Gesendet: Freitag, 1. Februar 2019 23:38 > An: Wayne Thayer > Cc: mozilla-dev-security-policy > > Betreff: Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR) > > On Fri, Feb 01, 2019 at 03:02:

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-01 Thread Kurt Roeckx via dev-security-policy
On Fri, Feb 01, 2019 at 03:02:17PM -0700, Wayne Thayer wrote: > It was pointed out to me that the OCSP status of the misissued certificate > that is valid for over 5 years is still "unknown" despite having been > revoked a week ago. I asked KIR about this in the bug [1] and am surprised > by their

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-02-01 Thread Wayne Thayer via dev-security-policy
It was pointed out to me that the OCSP status of the misissued certificate that is valid for over 5 years is still "unknown" despite having been revoked a week ago. I asked KIR about this in the bug [1] and am surprised by their response: This certificate is revoked on CRL. Because the

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-29 Thread Kurt Roeckx via dev-security-policy
On 2019-01-29 1:29, Wayne Thayer wrote: Piotr just filed an incident report on the misissuance that was reported on 18-January: https://bugzilla.mozilla.org/show_bug.cgi?id=1523186 I guess this part is not very clear to me: > We identified and removed from system the registration policy that

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-28 Thread Wayne Thayer via dev-security-policy
Piotr just filed an incident report on the misissuance that was reported on 18-January: https://bugzilla.mozilla.org/show_bug.cgi?id=1523186 The report discloses another misissuance that occurred during testing, resulting in a serverAuth certificate with a duration of over 5 years. On Sun, Jan

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-27 Thread piotr.grabowski--- via dev-security-policy
W dniu czwartek, 17 stycznia 2019 21:12:58 UTC+1 użytkownik Wayne Thayer napisał: > Hello Piotr, > > On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr > wrote: > > > Hello Wayne, > > > > > > > > I am very sorry for the delay. Please find below our answers to Ryan's > > questions. Regarding the

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-21 Thread Jakob Bohm via dev-security-policy
On 18/01/2019 19:21, piotr.grabow...@kir.pl wrote: W dniu piątek, 18 stycznia 2019 18:44:23 UTC+1 użytkownik Jakob Bohm napisał: On 17/01/2019 21:12, Wayne Thayer wrote: Hello Piotr, On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr wrote: Hello Wayne, I am very sorry for the delay.

Re: 46 Certificates issued with BR violations (KIR)

2019-01-18 Thread piotr.grabowski--- via dev-security-policy
W dniu poniedziałek, 8 października 2018 19:14:09 UTC+2 użytkownik Wayne Thayer napisał: > Thank you for the incident report. I have posted it to the bug: > https://bugzilla.mozilla.org/show_bug.cgi?id=1495497 > > On Mon, Oct 8, 2018 at 8:25 AM piotr.grabowski--- via dev-security-policy < >

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-18 Thread piotr.grabowski--- via dev-security-policy
W dniu czwartek, 17 stycznia 2019 21:12:58 UTC+1 użytkownik Wayne Thayer napisał: > Hello Piotr, > > On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr > wrote: > > > Hello Wayne, > > > > > > > > I am very sorry for the delay. Please find below our answers to Ryan's > > questions. Regarding the

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-18 Thread piotr.grabowski--- via dev-security-policy
W dniu piątek, 18 stycznia 2019 18:44:23 UTC+1 użytkownik Jakob Bohm napisał: > On 17/01/2019 21:12, Wayne Thayer wrote: > > Hello Piotr, > > > > On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr > > wrote: > > > >> Hello Wayne, > >> > >> > >> > >> I am very sorry for the delay. Please find

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-18 Thread piotr.grabowski--- via dev-security-policy
W dniu czwartek, 17 stycznia 2019 21:12:58 UTC+1 użytkownik Wayne Thayer napisał: > Hello Piotr, > > On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr > wrote: > > > Hello Wayne, > > > > > > > > I am very sorry for the delay. Please find below our answers to Ryan's > > questions. Regarding the

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-18 Thread Jakob Bohm via dev-security-policy
On 17/01/2019 21:12, Wayne Thayer wrote: Hello Piotr, On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr wrote: Hello Wayne, I am very sorry for the delay. Please find below our answers to Ryan's questions. Regarding the question why we didn't report this misissuance of this 1 certificate

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-17 Thread Wayne Thayer via dev-security-policy
Hello Piotr, On Thu, Jan 17, 2019 at 6:23 AM Grabowski Piotr wrote: > Hello Wayne, > > > > I am very sorry for the delay. Please find below our answers to Ryan's > questions. Regarding the question why we didn't report this misissuance > of this 1 certificate as separate incident in my opinion

RE: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-17 Thread Grabowski Piotr via dev-security-policy
. Pileckiego 65 02-781 Warszawa Tel. +48 22 545 56 76 Tel. +48 507 024 083 From: Wayne Thayer Sent: Thursday, January 17, 2019 12:55 AM To: Ryan Sleevi Cc: Grabowski Piotr ; mozilla-dev-security-policy Subject: Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR) Piotr, I

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-16 Thread Wayne Thayer via dev-security-policy
pressure on Verizon to deliver: >> >> o Policy field size validation – in our opinion it is simple change >> request and should be delivered ASAP. >> >> o native x509lint or zlint feature >> >> >> >> >> >> Piotr Grabowski >&g

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-11 Thread Ryan Sleevi via dev-security-policy
Grabowski > Linia biznesowa podpis elektroniczny > Krajowa Izba Rozliczeniowa S.A. > ul. rtm. W. Pileckiego 65 > 02-781 Warszawa > > Tel. +48 22 545 56 76 > > Tel. +48 507 024 083 > > > > *From:* Wayne Thayer > *Sent:* Wednesday, January 09, 2019 9:52 PM &g

RE: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-11 Thread Grabowski Piotr via dev-security-policy
6 Tel. +48 507 024 083 From: Wayne Thayer Sent: Wednesday, January 09, 2019 9:52 PM To: Grabowski Piotr Cc: r...@sleevi.com; mozilla-dev-security-policy Subject: Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR) KIR recently misissued another (pre-)certificate with an organi

Re: Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2019-01-09 Thread Wayne Thayer via dev-security-policy
18 at 8:16 AM Grabowski Piotr wrote: > Hello, > > My comments in blue. > > > -- > *Od:* Ryan Sleevi > *Wysłane:* czwartek, 11 października 2018 04:53 > *Do:* Grabowski Piotr > *DW:* Wayne Thayer; mozilla-dev-security-policy > *Tem

Odp.: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-12 Thread Grabowski Piotr via dev-security-policy
Hello, My comments in blue. Od: Ryan Sleevi Wysłane: czwartek, 11 października 2018 04:53 Do: Grabowski Piotr DW: Wayne Thayer; mozilla-dev-security-policy Temat: Re: Odp.: Odp.: 46 Certificates issued with BR violations (KIR) On Wed, Oct 10, 2018 at 4:33 PM

Re: Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-10 Thread Ryan Sleevi via dev-security-policy
On Wed, Oct 10, 2018 at 4:58 PM Grabowski Piotr wrote: > Hello Ryan, > > > In the design of this template, one of the concerns was about > understanding *how* a problem happened, not just how a CA responded. This > is why it includes text such as "This may include events before the > incident

Re: Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-10 Thread Ryan Sleevi via dev-security-policy
On Wed, Oct 10, 2018 at 4:33 PM Grabowski Piotr via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hello Wayne, > > - Is the new dual control process documented in a manner that will be > auditable by your external auditors? > > Yes, the new dual control process is

Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-10 Thread Grabowski Piotr via dev-security-policy
i Wysłane: wtorek, 9 października 2018 02:25:27 Do: Grabowski Piotr DW: mozilla-dev-security-policy Temat: Re: 46 Certificates issued with BR violations (KIR) On Mon, Oct 8, 2018 at 11:25 AM piotr.grabowski--- via dev-security-policy mailto:dev-security-policy@lists.mozilla.org>> wrote: Her

Odp.: Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-10 Thread Grabowski Piotr via dev-security-policy
2018 23:45:39 Do: Grabowski Piotr DW: mozilla-dev-security-policy Temat: Re: Odp.: 46 Certificates issued with BR violations (KIR) On Tue, Oct 9, 2018 at 5:30 AM Grabowski Piotr mailto:piotr.grabow...@kir.pl>> wrote: Hello Wayne, Please find our comments below: So far the process for

Re: Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-09 Thread Wayne Thayer via dev-security-policy
ems. Also, please respond to Ryan's email questioning how this happened. - Wayne > > > > Best Reagrds > Piotr Grabowski > -- > *Od:* Wayne Thayer > *Wysłane:* poniedziałek, 8 października 2018 19:13:46 > *Do:* Grabowski Piotr > *DW:* mozil

Odp.: 46 Certificates issued with BR violations (KIR)

2018-10-09 Thread Grabowski Piotr via dev-security-policy
to incident? Best Reagrds Piotr Grabowski Od: Wayne Thayer Wysłane: poniedziałek, 8 października 2018 19:13:46 Do: Grabowski Piotr DW: mozilla-dev-security-policy Temat: Re: 46 Certificates issued with BR violations (KIR) Thank you for the incident report. I have

Re: 46 Certificates issued with BR violations (KIR)

2018-10-08 Thread Ryan Sleevi via dev-security-policy
On Mon, Oct 8, 2018 at 11:25 AM piotr.grabowski--- via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Here's the incident report: > > 1.How your CA first became aware of the problem (e.g. via a problem > report submitted to your Problem Reporting Mechanism, via a > >

Re: 46 Certificates issued with BR violations (KIR)

2018-10-08 Thread Wayne Thayer via dev-security-policy
Thank you for the incident report. I have posted it to the bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1495497 On Mon, Oct 8, 2018 at 8:25 AM piotr.grabowski--- via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Here's the incident report: > > 1.How your CA first

46 Certificates issued with BR violations (KIR)

2018-10-08 Thread piotr.grabowski--- via dev-security-policy
Here's the incident report: 1.How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, via a discussion in mozilla.dev.security.policy, or via a Bugzilla bug), and the date. Email from Wayne Thayer Oct 1, 2018 2.