Re: Symantec Response V

2017-04-11 Thread Ryan Sleevi via dev-security-policy
> > > Hi Steve, Some follow-up questions: 1) Symantec stated "This information was in their management assertions, and repeated in the audit findings. So the poor audit situation was ongoing and known." a) Symantec did not meaningfully provide any explanation, now, or in the past, as to why it

Re: Symantec Response V

2017-04-11 Thread Gervase Markham via dev-security-policy
Hi Steve, Thank you for this. Issue V was indeed somewhat confused - my apologies. I have split it into Issue V, covering GeoRoot, and Issue W, covering the RAs. On 10/04/17 15:58, Steve Medin wrote: > Separately, Symantec operates two subordinate CAs solely for NTT > DoCoMo in an enterprise PKI

Symantec Response V

2017-04-10 Thread Steve Medin via dev-security-policy
Issue V: RA Program Audit Issues (2013 or earlier - January 2017) Symantec has had two different programs that involve delegated third parties associated with publicly trusted TLS and subject to third-party audits: our GeoRoot program and our RA/Affiliate program. GeoRoot refers to our program