Re: Policy 2.7 Proposal: Require EKUs in End-Entity Certificates

2019-04-01 Thread Brian Smith via dev-security-policy
Wayne Thayer via dev-security-policy wrote: > This leads to confusion such as [1] in > which certificates that are not intended for TLS or S/MIME fall within the > scope of our policies. > I disagree that there is any confusion. The policy is clear, as noted in

Policy 2.7 Proposal: Ban "No Stipulation", Blank, and Missing CP/CPS sections

2019-04-01 Thread Wayne Thayer via dev-security-policy
In October we discussed the use of "No Stipulation", empty sections, and blank sections in CP/CPSes. [1] The result was an update to the "Required Practices" wiki page. [2] I propose moving this into policy by adding the following paragraph to the bottom of section 3.3 "CPs and CPSes" In addition

Column added to AllCertificateRecordsCSVFormat report - CP/CPS Last Updated Date

2019-04-01 Thread Kathleen Wilson via dev-security-policy
All, The following report has been updated to add a column for "CP/CPS Last Updated Date". http://ccadb-public.secure.force.com/mozilla/AllCertificateRecordsCSVFormat Regards, Kathleen ___ dev-security-policy mailing list

Re: Apple: Non-Compliant Serial Numbers

2019-04-01 Thread Jakob Bohm via dev-security-policy
On 30/03/2019 22:16, certification_author...@apple.com wrote: > On March 30, Apple submitted an update to the original incident report > (https://bugzilla.mozilla.org/show_bug.cgi?id=1533655), which is reposted > below. >