Re: DRAFT May 2020 CA Communication/Survey

2020-05-01 Thread Matt Palmer via dev-security-policy
On Fri, May 01, 2020 at 04:48:28PM +, Corey Bonnell via dev-security-policy wrote: > I have briefly reviewed and would like to ask what is the intent of Item 4 > and the associated sub-items? The Browser Alignment draft ballot is under > discussion in the CAB Forum, so the intent behind the

Re: IdenTrust mis-issuance of an EV SSL Certificate

2020-05-01 Thread IdenTrust Inc via dev-security-policy
This issue has been corrected and a temporary solution to avoid recurrence was implemented on the same day it was encountered; we are still in the process of formulating permanent corrective measures and solution to share with the community via the expected formal Incident Report.

Re: DRAFT May 2020 CA Communication/Survey

2020-05-01 Thread Kathleen Wilson via dev-security-policy
On 5/1/20 10:18 AM, Corey Bonnell wrote: I agree that the intent of item 3 is clear, given the previous discussion on the topic [1]. However, there is no corresponding discussion on the Mozilla list (nor any Github issues [2]) for item 4 and the associated sub-items, which is why I asked for

Re: DRAFT May 2020 CA Communication/Survey

2020-05-01 Thread Kathleen Wilson via dev-security-policy
On 5/1/20 9:48 AM, Corey Bonnell wrote: Hi Kathleen, Thank you for sending out this notification of the draft survey. I have briefly reviewed and would like to ask what is the intent of Item 4 and the associated sub-items? The Browser Alignment draft ballot is under discussion in the CAB

RE: DRAFT May 2020 CA Communication/Survey

2020-05-01 Thread Corey Bonnell via dev-security-policy
> Not Kathleen here, but it seems to make sense to me, for the same reason > Item 3 makes sense. That is, in Item 3, Apple's deployed a policy, and > there's > a question about if/when Mozilla should do the same. Item 4 seems similar - > 4.1 is a Microsoft requirement, 4.2 is an existing Mozilla

Re: DRAFT May 2020 CA Communication/Survey

2020-05-01 Thread Ryan Sleevi via dev-security-policy
On Fri, May 1, 2020 at 12:48 PM Corey Bonnell via dev-security-policy wrote: > > Hi Kathleen, > Thank you for sending out this notification of the draft survey. I have > briefly reviewed and would like to ask what is the intent of Item 4 and the > associated sub-items? The Browser Alignment

RE: DRAFT May 2020 CA Communication/Survey

2020-05-01 Thread Corey Bonnell via dev-security-policy
Hi Kathleen, Thank you for sending out this notification of the draft survey. I have briefly reviewed and would like to ask what is the intent of Item 4 and the associated sub-items? The Browser Alignment draft ballot is under discussion in the CAB Forum, so the intent behind the shift of the