Re: Symantec Response N

2017-04-10 Thread Ryan Sleevi via dev-security-policy
Hi Steve, Quick questions: 1) What steps, specifically, has Symantec taken to ensure such clarity is provided in the future? 2) What steps, specifically, has Symantec taken to ensure appropriate review prior to the execution of such processes? These questions apply to any process involving CA

Symantec Response N

2017-04-10 Thread Steve Medin via dev-security-policy
Issue N: Premature Manual Signing Using SHA-1 (July 2016) This matter represents the first time any CA attempted to follow the exception process which was developed over the course of weeks, beginning at the Bilbao CABF face-to-face meeting in May 2016, and with the input of our partners.