Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-06 Thread Tim Shirley via dev-security-policy
a.org" Subject: Re: Submission to ct-logs of the final certificate when there is already a pre-certificate I think (3) shouldn't be considered any different from (1) -- they're only meaningfully different if you make a lot of assumptions about how it's stored and transp

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-06 Thread Alex Gaynor via dev-security-policy
wrote: > >> > >>> On 02/04/2018 18:26, Tom Delmas wrote: > >>> > >>>> Following the discussion on > >>>> https://scanmail.trustwave.com/?c=4062&d=l_ > TG2r42aQmbn72ySdqaNlBjW-xvJAqoIpJG1bH1_Q&s=5&

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-06 Thread Tim Shirley via dev-security-policy
On 02/04/2018 18:26, Tom Delmas wrote: >>> >>>> Following the discussion on >>>> https://scanmail.trustwave.com/?c=4062&d=l_TG2r42aQmbn72ySdqaNlBjW-xvJAqoIpJG1bH1_Q&s=5&u=https%3a%2f%2fcommunity%2eletsencrypt%2eorg%2ft%2fnon-logging-of-final-cer

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-05 Thread Jakob Bohm via dev-security-policy
: Following the discussion on https://community.letsencrypt.org/t/non-logging-of-final-certificates/58394 What is the position of Mozilla about the submission to ct-logs of the final certificate when there is already a pre-certificate? As it helps discover bugs ( https://twitter.com/_quirins/status

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-05 Thread Matt Palmer via dev-security-policy
; > > Following the discussion on > > > > https://community.letsencrypt.org/t/non-logging-of-final-certificates/58394 > > > > > > > > What is the position of Mozilla about the submission to ct-logs of the > > > > final certificate when there is a

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-05 Thread Alex Gaynor via dev-security-policy
t;> >>> On 02/04/2018 18:26, Tom Delmas wrote: >>> >>>> Following the discussion on >>>> https://community.letsencrypt.org/t/non-logging-of-final-cer >>>> tificates/58394 >>>> >>>> What is the position of Mozilla about

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-05 Thread Jakob Bohm via dev-security-policy
Mozilla about the submission to ct-logs of the final certificate when there is already a pre-certificate? As it helps discover bugs ( https://twitter.com/_quirins/status/979788044994834434 ), it helps accountability of CAs and it's easily enforceable, I feel that it should be mandatory. If s

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-03 Thread Matt Palmer via dev-security-policy
sition of Mozilla about the submission to ct-logs of the > > final certificate when there is already a pre-certificate? > > > > As it helps discover bugs ( > > https://twitter.com/_quirins/status/979788044994834434 ), it helps > > accountability of CAs and it's easily enfor

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-02 Thread Jakob Bohm via dev-security-policy
On 02/04/2018 18:26, Tom Delmas wrote: Following the discussion on https://community.letsencrypt.org/t/non-logging-of-final-certificates/58394 What is the position of Mozilla about the submission to ct-logs of the final certificate when there is already a pre-certificate? As it helps

Re: Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-02 Thread Alex Gaynor via dev-security-policy
ubmission to ct-logs of the > final certificate when there is already a pre-certificate? > > As it helps discover bugs ( https://twitter.com/_quirins/s > tatus/979788044994834434 ), it helps accountability of CAs and it's > easily enfo

Submission to ct-logs of the final certificate when there is already a pre-certificate

2018-04-02 Thread Tom Delmas via dev-security-policy
Following the discussion on https://community.letsencrypt.org/t/non-logging-of-final-certificates/58394 What is the position of Mozilla about the submission to ct-logs of the final certificate when there is already a pre-certificate? As it helps discover bugs ( https://twitter.com/_quirins