Re: SHA-1 serverAuth cert issued by HydrantID (QuoVadis) in January 2017

2017-02-20 Thread Gervase Markham via dev-security-policy
Hi Stephen, On 16/02/17 18:37, Stephen Davidson wrote: > Incident Report Thank you for your prompt and detailed incident report. It seems to me that this highlights the particular extra care that needs to be taken by all CAs regarding manual issuances which do not use the normal software into

RE: SHA-1 serverAuth cert issued by HydrantID (QuoVadis) in January 2017

2017-02-16 Thread Stephen Davidson via dev-security-policy
rg] On Behalf Of Rob Stradling via dev-security-policy Sent: Wednesday, February 15, 2017 7:14 PM To: mozilla-dev-security-pol...@lists.mozilla.org <dev-security-policy@lists.mozilla.org> Subject: SHA-1 serverAuth cert issued by HydrantID (QuoVadis) in January 2017 This currently unrevoked c

SHA-1 serverAuth cert issued by HydrantID (QuoVadis) in January 2017

2017-02-15 Thread Rob Stradling via dev-security-policy
This currently unrevoked cert has the serverAuth EKU and dNSName=qvsslrca3-v.quovadisglobal.com: https://crt.sh/?id=83114602 Its issuer is trusted for serverAuth by Mozilla: https://crt.sh/?caid=1333 -- Rob Stradling Senior Research & Development Scientist COMODO - Creating Trust Online