Incident Report - CAA misissuance (was Re: Lack of CAA checking at Comodo)

2017-09-12 Thread Rob Stradling via dev-security-policy
On 11/09/17 15:30, Rob Stradling via dev-security-policy wrote: Hi Hanno.  Thanks for reporting this to us.  We acknowledge the problem, and as I mentioned at [1], we took steps to address it this morning. We will follow-up with an incident report ASAP. INCIDENT REPORT We received two

Re: Lack of CAA checking at Comodo

2017-09-11 Thread Rob Stradling via dev-security-policy
Comodo isn't checking CAA at all. There's also a bug in the Mozilla bug tracker: https://bugzilla.mozilla.org/show_bug.cgi?id=1398545 I was originally informed about the lack of CAA checking at Comodo by Michael Kliewe from the mail provider mail.de. However that was before CAA became mandatory

Lack of CAA checking at Comodo

2017-09-11 Thread Hanno Böck via dev-security-policy
checking CAA at all. There's also a bug in the Mozilla bug tracker: https://bugzilla.mozilla.org/show_bug.cgi?id=1398545 I was originally informed about the lack of CAA checking at Comodo by Michael Kliewe from the mail provider mail.de. However that was before CAA became mandatory. But even back