Re: Incident Report - Entrust Datacard issued certificates with the incorrect Organization Name

2019-03-15 Thread Ryan Sleevi via dev-security-policy
To echo Tim's remarks, this is really two issues: 1) A failure of controls (the current incident report) 2) A failure to revoke I'm rather concerned about #2 and the lack of detail presently provided regarding it, as well as the one week wait to filing the incident report for #1.

RE: Incident Report - Entrust Datacard issued certificates with the incorrect Organization Name

2019-03-15 Thread Tim Hollebeek via dev-security-policy
ev-security-pol...@lists.mozilla.org > Subject: Incident Report - Entrust Datacard issued certificates with the > incorrect Organization Name > > On March 7, 2019, Entrust Datacard discovered that SSL certificates with the > wrong Organization value were issued to a customer. The investig

Incident Report - Entrust Datacard issued certificates with the incorrect Organization Name

2019-03-15 Thread Bruce via dev-security-policy
On March 7, 2019, Entrust Datacard discovered that SSL certificates with the wrong Organization value were issued to a customer. The investigation was completed 15 March 2019. Details of the incident report can be found here, https://bugzilla.mozilla.org/show_bug.cgi?id=1535735. All