Re: Certum CA - Unallowed key usage for EC public key (Key Encipherment)

2018-10-24 Thread Wojciech TrapczyƄski via dev-security-policy
In addition to the things that I described in the Incident Report we have added to our periodic verification procedure the point where a check of "CA/B Forum lint: Summary" site from crt.sh is required at least every 5 days. It should help us to detect any misissuance related to inconsistency

Re: Certum CA - Unallowed key usage for EC public key (Key Encipherment)

2018-10-12 Thread Wayne Thayer via dev-security-policy
Wojciech, Thank you for the incident report. I believe it does a good job of explaining how you will prevent this specific problem from happening again, but it does not address the broader problem of misissuance and Certum's failure to detect it. How can the Mozilla community be assured that