Re: AC Camerfirma's undisclosed itermediate certificates incident report

2018-08-03 Thread Juan Angel Martin via dev-security-policy
El jueves, 2 de agosto de 2018, 15:50:44 (UTC+2), Kurt Roeckx escribió: > On Thu, Aug 02, 2018 at 06:19:42AM -0700, Juan Angel Martin via > dev-security-policy wrote: > > > > 6) Explanation about how and why the mistakes were made or bugs introduced, > > and how they avoided detection until no

Re: AC Camerfirma's undisclosed itermediate certificates incident report

2018-08-02 Thread Kurt Roeckx via dev-security-policy
On Thu, Aug 02, 2018 at 06:19:42AM -0700, Juan Angel Martin via dev-security-policy wrote: > > 6) Explanation about how and why the mistakes were made or bugs introduced, > and how they avoided detection until now. > > The procedure established to publish the CAs into CCADB wasn't correct caus

AC Camerfirma's undisclosed itermediate certificates incident report

2018-08-02 Thread Juan Angel Martin via dev-security-policy
Hello, 1) How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a Bugzilla bug, or internal self-audit), and the time and date. We receive a communication via Buzilla from Wayne Tha