Re: Policy 2.6 Proposal: Updated criteria for including new CAs based on recent discussion

2018-03-23 Thread Wayne Thayer via dev-security-policy
I've made the additional change proposed above to the 2.6 branch: https://github.com/mozilla/pkipolicy/commit/13ce71ab3936e721236b8c9f8753f253fb7f3750 On Tue, Mar 20, 2018 at 2:23 PM, Ryan Sleevi wrote: > Ah, good point. Yeah, I think that's a perfectly reasonable change. > > On Tue, Mar 20, 20

Re: Policy 2.6 Proposal: Updated criteria for including new CAs based on recent discussion

2018-03-20 Thread Ryan Sleevi via dev-security-policy
Ah, good point. Yeah, I think that's a perfectly reasonable change. On Tue, Mar 20, 2018 at 2:45 PM, Wayne Thayer via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Tue, Mar 20, 2018 at 8:22 AM, Ryan Sleevi wrote: > > > > > So, one aspect of this is the recently discuss

Re: Policy 2.6 Proposal: Updated criteria for including new CAs based on recent discussion

2018-03-20 Thread Wayne Thayer via dev-security-policy
On Tue, Mar 20, 2018 at 8:22 AM, Ryan Sleevi wrote: > > So, one aspect of this is the recently discussed risk - that is, a CA that > provides value for only 10 users presents a substantial amount of risk to > all Mozilla users, for both compromise and non-compliance. This is, > admittedly, a subj

Re: Policy 2.6 Proposal: Updated criteria for including new CAs based on recent discussion

2018-03-20 Thread Ryan Sleevi via dev-security-policy
On Mon, Mar 19, 2018 at 6:26 PM, Wayne Thayer via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > A few months ago, we discussed our root inclusion criteria [1], and came to > a conclusion that I summarized and proposed in policy as follows: > > I would like to thank everyone

Policy 2.6 Proposal: Updated criteria for including new CAs based on recent discussion

2018-03-19 Thread Wayne Thayer via dev-security-policy
A few months ago, we discussed our root inclusion criteria [1], and came to a conclusion that I summarized and proposed in policy as follows: I would like to thank everyone for your constructive input on this topic. > At the outset I stated a desire to ‘establish some objective criteria that > can