Re: AIA CA Issuer field pointing to PEM encoded certs

2020-05-14 Thread Nuno Ponte via dev-security-policy
Dear Hanno, Many thanks for the report. This has now been fixed for Multicert and an incident report was filed at Bugzilla: https://bugzilla.mozilla.org/show_bug.cgi?id=1637093 Best regards, NP segunda-feira, 11 de Maio de 2020 às 17:09:08 UTC+1, Hanno Böck escreveu: > Hi, > > As I

Re: AIA CA Issuer field pointing to PEM encoded certs

2020-05-13 Thread Hanno Böck via dev-security-policy
Update: All 4 CAs have corrected the certs and are now serving DER encoded intermediates at the URLs. -- Hanno Böck https://hboeck.de/ ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org

AIA CA Issuer field pointing to PEM encoded certs

2020-05-11 Thread Hanno Böck via dev-security-policy
Hi, As I mentioned in my previous mail I found some instances of CAs pointing to PEM encoded certificates in their AIA fields, while they should be DER encoded. I found such instances for 4 CAs, I'll list them with one example cert and the URL of the referenced intermediate.