Re: GoDaddy Revocations Due to a Variety of Issues

2018-08-09 Thread Ryan Sleevi via dev-security-policy
On Thu, Aug 9, 2018 at 8:24 AM, Nick Lamb via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Fri, 20 Jul 2018 21:38:45 -0700 > Peter Bowen via dev-security-policy > wrote: > > > https://crt.sh/?id=294808610=zlint,cablint is one of the > > certificates. It is not clear

Re: GoDaddy Revocations Due to a Variety of Issues

2018-08-09 Thread Nick Lamb via dev-security-policy
On Fri, 20 Jul 2018 21:38:45 -0700 Peter Bowen via dev-security-policy wrote: > https://crt.sh/?id=294808610=zlint,cablint is one of the > certificates. It is not clear to me that there is an error here. > The DNS names in the SAN are correctly encoded and the Common Name in > the subject has

Re: GoDaddy Revocations Due to a Variety of Issues

2018-08-01 Thread Wayne Thayer via dev-security-policy
Thank you for this report Daymion. 3 of the issues were recent: | e_dnsname_not_valid_tld, | | |e_subject_common_name_not_from_san,| | |e_dnsname_bad_character_in_label |4

Re: GoDaddy Revocations Due to a Variety of Issues

2018-07-26 Thread Peter Bowen via dev-security-policy
On Wed, Jul 25, 2018 at 2:08 PM Joanna Fox via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Friday, July 20, 2018 at 9:39:04 PM UTC-7, Peter Bowen wrote: > > > *Total of 17 certificates issued in 2018 were revoked due to invalid > > > extended ascii characters.

Re: GoDaddy Revocations Due to a Variety of Issues

2018-07-25 Thread Joanna Fox via dev-security-policy
On Friday, July 20, 2018 at 9:39:04 PM UTC-7, Peter Bowen wrote: > On Fri, Jul 20, 2018 at 6:39 PM Daymion Reynolds via dev-security-policy < > dev-security-policy@lists.mozilla.org> wrote: > > > The certificates were identified by analyzing results from both zlint and > > certlint. We also

Re: GoDaddy Revocations Due to a Variety of Issues

2018-07-23 Thread Daymion Reynolds via dev-security-policy
Once we have the CertLint change pull requests done we will submit them to this thread. They were much more involved, and many times more numerous. It is worth a write up on where they overlap and diverge. Daymion On Friday, July 20, 2018 at 9:39:04 PM UTC-7, Peter Bowen wrote: > On Fri, Jul

Re: GoDaddy Revocations Due to a Variety of Issues

2018-07-20 Thread Peter Bowen via dev-security-policy
On Fri, Jul 20, 2018 at 6:39 PM Daymion Reynolds via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > The certificates were identified by analyzing results from both zlint and > certlint. We also verified all lint findings against current and past BRs. > We discovered