Re: Maximal validity of the test TLS certificate issued by a private PKI system

2018-12-13 Thread Sándor dr . Szőke via dev-security-policy
2018. december 13., csütörtök 7:35:32 UTC+1 időpontban Dean Coclin a következőt írta: > My opinion: > The CA/B Forum Baseline Requirements only apply to certificates which chain > to publicly trusted roots. This is made clear in the preamble of the > document: > > This document describes an

Re: Maximal validity of the test TLS certificate issued by a private PKI system

2018-12-12 Thread Dean Coclin via dev-security-policy
My opinion: The CA/B Forum Baseline Requirements only apply to certificates which chain to publicly trusted roots. This is made clear in the preamble of the document: This document describes an integrated set of technologies, protocols, identity-proofing, lifecycle management, and auditing

Re: Maximal validity of the test TLS certificate issued by a private PKI system

2018-12-12 Thread Wayne Thayer via dev-security-policy
On Wed, Dec 12, 2018 at 9:13 AM Sándor dr. Szőke via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > > Thank you for the detailed answer, I think that the requirement is clear > for us now. > > The misunderstanding was caused by the different usage of the term 'Test >

Re: Maximal validity of the test TLS certificate issued by a private PKI system

2018-12-12 Thread Sándor dr . Szőke via dev-security-policy
2018. december 11., kedd 19:51:45 UTC+1 időpontban Doug Beattie a következőt írta: > Option 1 is the intended interpretation. We specified 30 days because the > tokens used for domain validation (Random Number) need to have a useful life > of 30 days. The 30-day usage period needed to be put

RE: Maximal validity of the test TLS certificate issued by a private PKI system

2018-12-11 Thread Doug Beattie via dev-security-policy
Option 1 is the intended interpretation. We specified 30 days because the tokens used for domain validation (Random Number) need to have a useful life of 30 days. The 30-day usage period needed to be put into the definition of the Test Certificate, or into Method 3.2.2.4.9, and we selected the