Re: Audit Reminders for Intermediate Certs

2020-05-07 Thread Kathleen Wilson via dev-security-policy
On 5/6/20 5:19 AM, Ryan Sleevi wrote: Should we be creating CA incidents for repeats? I wasn’t sure if this was just an administrative hiccup on the Mozilla side in processing the case, or if this is a matter where the CA is not disclosing in a timely fashion. CAs directly add audit

Re: DRAFT May 2020 CA Communication/Survey

2020-05-07 Thread Kathleen Wilson via dev-security-policy
> I have drafted a potential CA Communication and survey, and will greatly > appreciate your input on it. > > https://wiki.mozilla.org/CA/Communications#May_2020_CA_Communication > > Direct link to read-only copy of the draft survey: >

GRCA: Out-of-date CPS provided in CCADB

2020-05-07 Thread Matt Palmer via dev-security-policy
In trying to validate the problem reporting e-mail address for https://crt.sh/?id=657220608, I grovelled through the CCADB CSV-o'-Doom (freshly downloaded for that "new CSV" smell ), and the CPS link therein refers to http://grca.nat.gov.tw/download/GPKI_CP_eng_v1.7.pdf which, at the time of

Filtering on problem reporting e-mail addresses

2020-05-07 Thread Matt Palmer via dev-security-policy
This has happened twice now, with two different CAs, so I'm going to raise it as a general issue. I've had one CA reject e-mails because the HELO name wasn't to their liking (which I was able to fix). The other, which has just started happening now, is utterly inscrutible -- "550 Administrative