RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-06-05 Thread Daniela Hood via dev-security-policy
leevi.com>> Sent: Friday, May 29, 2020 7:52 AM To: Daniela Hood mailto:dxh...@godaddy.com>> Cc: dev-security-policy@lists.mozilla.org<mailto:dev-security-policy@lists.mozilla.org> Subject: Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours Notic

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-06-03 Thread Cynthia Revström via dev-security-policy
iginal Message- > From: dev-security-policy > On Behalf Of Daniela Hood via dev-security-policy > Sent: Friday, May 29, 2020 9:16 PM > To: 'r...@sleevi.com' > Cc: dev-security-policy@lists.mozilla.org > Subject: RE: GoDaddy: Failure to revoke certificate with compromised key &

RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-06-03 Thread Daniela Hood via dev-security-policy
via dev-security-policy Sent: Friday, May 29, 2020 9:16 PM To: 'r...@sleevi.com' Cc: dev-security-policy@lists.mozilla.org Subject: RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours Notice: This email is from an external sender. GoDaddy acknowledges the inquiry

RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-29 Thread Daniela Hood via dev-security-policy
dxh...@godaddy.com> From: Ryan Sleevi Sent: Friday, May 29, 2020 7:52 AM To: Daniela Hood Cc: dev-security-policy@lists.mozilla.org Subject: Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours Notice: This email is from an external sender. Thank you for your

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-29 Thread Ryan Sleevi via dev-security-policy
; > > -Original Message- > From: Nick Lamb > Sent: Friday, May 22, 2020 4:50 PM > To: dev-security-policy@lists.mozilla.org > Cc: Daniela Hood > Subject: Re: GoDaddy: Failure to revoke certificate with compromised key > within 24 hours > > Notice: This email i

RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-28 Thread Daniela Hood via dev-security-policy
to avoid such errors from occurring. Daniela Hood GoDaddy -Original Message- From: Nick Lamb Sent: Friday, May 22, 2020 4:50 PM To: dev-security-policy@lists.mozilla.org Cc: Daniela Hood Subject: Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours Notice

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-22 Thread Nick Lamb via dev-security-policy
On Fri, 22 May 2020 22:48:42 + Daniela Hood via dev-security-policy wrote: > Hello, > > Thank you for all the comments in this thread. We filed an incident > report related to the revocation timing that can be followed here: > https://bugzilla.mozilla.org/show_bug.cgi?id=1640310. We also

RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-22 Thread Daniela Hood via dev-security-policy
and provided feedback to the employee. Daniela Hood GoDaddy -Original Message- From: dev-security-policy On Behalf Of Matt Palmer via dev-security-policy Sent: Thursday, May 21, 2020 6:32 PM To: dev-security-policy@lists.mozilla.org Subject: Re: GoDaddy: Failure to revoke certificate

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-21 Thread Matt Palmer via dev-security-policy
On Thu, May 21, 2020 at 02:01:49PM -0700, Daniela Hood via dev-security-policy wrote: > After that we followed the Baseline Requirements 4.9.1 That says: "The CA > obtains evidence that the Subscriber's Private Key corresponding to the > Public Key in the Certificate suffered a Key Compromise;"

RE: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-21 Thread Jeremy Rowley via dev-security-policy
Sent: Thursday, May 21, 2020 3:25 PM To: Daniela Hood Cc: Mozilla Subject: Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours On Thu, May 21, 2020 at 02:01:49PM -0700, Daniela Hood via dev-security-policy wrote: > Hello Sandy, > > GoDaddy received

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-21 Thread Kurt Roeckx via dev-security-policy
On Thu, May 21, 2020 at 02:01:49PM -0700, Daniela Hood via dev-security-policy wrote: > Hello Sandy, > > GoDaddy received an email on Friday, May 7, 2020 12:06 UTC, reporting a key > compromise, by Sandy. Once received our team started working on making sure > that the certificate had indeed a

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-21 Thread Daniela Hood via dev-security-policy
On Thursday, May 21, 2020 at 10:06:02 AM UTC-7, sandy...@gmail.com wrote: > On Thursday, May 21, 2020 at 12:33:25 PM UTC+10, Matt Palmer wrote: > > On Tue, May 19, 2020 at 07:33:00PM -0700, sandybar497--- via > > dev-security-policy wrote: > > > Here are the original headers (omitting my email) >

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-21 Thread sandybar497--- via dev-security-policy
On Thursday, May 21, 2020 at 12:33:25 PM UTC+10, Matt Palmer wrote: > On Tue, May 19, 2020 at 07:33:00PM -0700, sandybar497--- via > dev-security-policy wrote: > > Here are the original headers (omitting my email) > > > > *** > > > > MIME-Version: 1.0 > > Date: Thu, 7 May 2020 12:07:07 + >

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-20 Thread Matt Palmer via dev-security-policy
On Tue, May 19, 2020 at 07:33:00PM -0700, sandybar497--- via dev-security-policy wrote: > Here are the original headers (omitting my email) > > *** > > MIME-Version: 1.0 > Date: Thu, 7 May 2020 12:07:07 + > Message-ID: > > Subject: Certificate Problem Report - compromised key > From:

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-20 Thread sandybar497--- via dev-security-policy
On Wednesday, May 20, 2020 at 3:03:01 AM UTC+10, Ryan Sleevi wrote: > On Tue, May 19, 2020 at 12:38 PM sandybar497--- via > dev-security-policy wrote: > > I actually submitted this post 6 days ago and was only just approved > > today.. is there a lack of resources approving blog posts? just

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-19 Thread Ryan Sleevi via dev-security-policy
On Tue, May 19, 2020 at 12:38 PM sandybar497--- via dev-security-policy wrote: > I actually submitted this post 6 days ago and was only just approved today.. > is there a lack of resources approving blog posts? just don't see how it's > helpful when posts show up so late. It looks like you may

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-19 Thread sandybar497--- via dev-security-policy
On Friday, May 15, 2020 at 7:30:45 AM UTC+10, Ryan Sleevi wrote: > Do you have a copy of the OCSP response? > > With such issues, we may need signed artifacts to demonstrate > non-compliance. For example, it shows as revoked via both OCSP and CRL > for me. > > On Thu, May 14, 2020 at 4:32 PM

Re: GoDaddy: Failure to revoke certificate with compromised key within 24 hours

2020-05-14 Thread Ryan Sleevi via dev-security-policy
Do you have a copy of the OCSP response? With such issues, we may need signed artifacts to demonstrate non-compliance. For example, it shows as revoked via both OCSP and CRL for me. On Thu, May 14, 2020 at 4:32 PM sandybar497--- via dev-security-policy wrote: > > On 7 May 2020 at 12:07:07 PM