CA report with CAA and Problem Reporting info

2017-05-25 Thread Kathleen Wilson via dev-security-policy
All, We have added the following two reports to https://wiki.mozilla.org/CA/Included_Certificates 1) CAs with Included Certificates https://ccadb-public.secure.force.com/mozilla/CAInformationReport 2) CAs with Included Certificates (CSV)

Re: Google Plan for Symantec posted

2017-05-25 Thread Gervase Markham via dev-security-policy
Here's my roundup of things I think we should require of Symantec. * Mozilla would wish, after 2017-08-08, to alter Firefox such that it trusts certificates issued in the "new PKI" directly by embedding a set of certs or trust anchors which are part of that PKI, and can therefore distrust any new

Re: Google Plan for Symantec posted

2017-05-25 Thread Gervase Markham via dev-security-policy
On 24/05/17 16:33, Peter Bowen wrote: > Can you clarify the meaning of "new PKI"? I can see two reasonable > interpretations: > 2) The new PKI includes both new offline CAs that meet the > requirements to be Root CAs and new subordinate CAs that issue > end-entity certificates. the The new

Re: Guang Dong Certificate Authority (GDCA) root inclusion request

2017-05-25 Thread wangsn1206--- via dev-security-policy
Hi All, We have just updated and published our CP/CPS, and the latest versions are available at: CP V1.7: https://bug1128392.bmoattachments.org/attachment.cgi?id=8871236 CPS V4.6: https://bug1128392.bmoattachments.org/attachment.cgi?id=8871237 EV CP V1.5: