Re: More SHA-1 certs

2016-02-06 Thread Rob Stradling
On 05/02/16 21:43, Charles Reiss wrote: On 02/05/16 20:13, martin.suc...@gmail.com wrote: Here's a list of all certificates with SHA-1 signatures and notBefore >= 2016-01-01, logged in the Certificate Transparency Log: https://crt.sh/?cablint=211=2016-01-01 Some notes on how these look as of

RE: More SHA-1 certs

2016-02-06 Thread Yuhong Bao
> "Class 3 Public Primary Certification Authority - G2" is still trusted > for serverAuthentication in Microsoft's root program. Actually the same is true for the G1 one too (they just added the trust back). Yuhong Bao

Policy revision proposal - transitive disclosure exception

2016-02-06 Thread Peter Bowen
The Mozilla CA Certificate policy says, in part: "8. All certificates that are capable of being used to issue new certificates, and which directly or transitively chain to a certificate included in Mozilla’s CA Certificate Program, MUST be operated in accordance with Mozilla’s CA Certificate