Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-12-12 Thread Wayne Thayer via dev-security-policy
I have update the bug [1] and recommended approval of this emSign root inclusion request. - Wayne [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1442337 On Tue, Nov 27, 2018 at 10:19 AM Wayne Thayer wrote: > I've reviewed the updated CPS and these period-of-time audit statements - > I have

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-11-27 Thread Vijay Kumar via dev-security-policy
Hi, Happy to inform the availibility of Period of Time Audit reports. The audit reports are dated 08-Oct-2018, and the corresponding Webtrust seals are available at https://repository.emsign.com Links to individual audit reports. WebTrust CA:

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-27 Thread Vijay Kumar via dev-security-policy
There is an update made to emSign CP/CPS and latest version 1.05 is published. The change covers more clarity on email verification methods. It also covers couple of structural updates to CP/CPS in line with RFC 3647. (Change History is part of the document, at the end.) URL for latest CPS:

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-16 Thread Vijay via dev-security-policy
On Friday, October 12, 2018 at 4:07:11 AM UTC+8, Wayne Thayer wrote: > This request is for inclusion of these four emSign roots operated by > eMudhra in bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1442337 > > * BR Self Assessment is here: >

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-16 Thread Vijay via dev-security-policy
On Friday, October 12, 2018 at 6:47:12 AM UTC+8, Samuel Pinder wrote: > Visiting the www.emsign.com homepage brings up a list of proposed products. > Currently, in the "Types of Certificate" table halfway down the page is the > following: > Wildcard SSL - OV > Wildcard SSL - EV > UCC Wildcard

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-16 Thread Vijay via dev-security-policy
On Friday, October 12, 2018 at 6:33:53 AM UTC+8, Matt Palmer wrote: > On Thu, Oct 11, 2018 at 02:36:18PM -0700, Wayne Thayer via > dev-security-policy wrote: > > Nick - I expect an emSign representative to respond to all of your > > questions, but their information request indicates that they

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-16 Thread vijay--- via dev-security-policy
On Friday, October 12, 2018 at 5:07:55 AM UTC+8, Nick Lamb wrote: > On Thu, 11 Oct 2018 13:06:46 -0700 > Wayne Thayer via dev-security-policy > wrote: > > > This request is for inclusion of these four emSign roots operated by > > eMudhra in bug:

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-16 Thread vijay--- via dev-security-policy
On Friday, October 12, 2018 at 6:19:52 AM UTC+8, Matt Palmer wrote: > On Thu, Oct 11, 2018 at 01:06:46PM -0700, Wayne Thayer via > dev-security-policy wrote: > > * The CPS allows “external issuing CAs” but does not clearly state that the > > requirements of BR section 1.3.2 will be met. emSign

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-11 Thread Samuel Pinder via dev-security-policy
Visiting the www.emsign.com homepage brings up a list of proposed products. Currently, in the "Types of Certificate" table halfway down the page is the following: Wildcard SSL - OV Wildcard SSL - EV UCC Wildcard SSL - DV UCC Wildcard SSL - OV UCC Wildcard SSL - EV That's not a good sign at

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-11 Thread Matt Palmer via dev-security-policy
On Thu, Oct 11, 2018 at 02:36:18PM -0700, Wayne Thayer via dev-security-policy wrote: > Nick - I expect an emSign representative to respond to all of your > questions, but their information request indicates that they have been > operating the Indian Government Root for more than 10 years and

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-11 Thread Matt Palmer via dev-security-policy
On Thu, Oct 11, 2018 at 01:06:46PM -0700, Wayne Thayer via dev-security-policy wrote: > * The CPS allows “external issuing CAs” but does not clearly state that the > requirements of BR section 1.3.2 will be met. emSign made the following > comment in response to this concern: “In the CP/CPS,

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-11 Thread Wayne Thayer via dev-security-policy
Nick - I expect an emSign representative to respond to all of your questions, but their information request indicates that they have been operating the Indian Government Root for more than 10 years and have issued over 35 million certificates:

Re: Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-11 Thread Nick Lamb via dev-security-policy
On Thu, 11 Oct 2018 13:06:46 -0700 Wayne Thayer via dev-security-policy wrote: > This request is for inclusion of these four emSign roots operated by > eMudhra in bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1442337 I would like to read more about eMudhra / emSign. I have never heard of

Request to Include emSign Root CA - G1, emSign Root CA - G3, emSign Root CA - C1, and emSign Root CA - C3

2018-10-11 Thread Wayne Thayer via dev-security-policy
This request is for inclusion of these four emSign roots operated by eMudhra in bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1442337 * BR Self Assessment is here: https://bug1442337.bmoattachments.org/attachment.cgi?id=8955225 * Summary of Information Gathered and Verified: