Policy 2.7.1: MRSP Issue #154: Require Management Assertions to list Non-compliance

2020-10-22 Thread Ben Wilson via dev-security-policy
The purpose of this email is to begin public discussion on an addition to section 2.4 of the Mozilla Root Store Policy. Issue #154 in GitHub proposes to require that management assertions (CA disclosures to auditors) provide written mention of all

Policy 2.7.1: MRSP Issue #187: Require disclosure of incidents in Audit Reports

2020-10-22 Thread Ben Wilson via dev-security-policy
The purpose of this email is to begin public discussion on the addition of a subsection 11 to section 3.1.4 of the Mozilla Root Store Policy. Issue #187 in GitHub proposes to require audit reports to list all incidents occurring (or open) during