Re: Draft Security Blog about v2.5 of Root Store Policy

2017-09-07 Thread Kathleen Wilson via dev-security-policy
On Thursday, September 7, 2017 at 1:23:17 AM UTC-7, Buschart, Rufus wrote: > I have a question regarding the meaning of: > > > * The latest versions of the WebTrust and ETSI audit criteria are now > > required, and auditors are required to be appropriately qualified. I will delete that sentence

RE: Draft Security Blog about v2.5 of Root Store Policy

2017-09-07 Thread Buschart, Rufus via dev-security-policy
Hello Kathleen! Thank you for sharing your draft version. I have a question regarding the meaning of: > * The latest versions of the WebTrust and ETSI audit criteria are now > required, and auditors are required to be appropriately qualified. Will you still accept ETSI TS 102 042 audits or

Re: Draft Security Blog about v2.5 of Root Store Policy

2017-09-06 Thread David E. Ross via dev-security-policy
On 9/6/2017 11:22 AM, Kathleen Wilson wrote [in part]: > * Our policy on root certificates being transferred from one > organization or location to another has been updated and included in > the main policy. Trust is not transferable; Mozilla will not > automatically trust the purchaser of a root