Re: Verifying Auditor Qualifications

2020-06-04 Thread Kathleen Wilson via dev-security-policy
On 6/4/20 1:25 AM, Arvid Vermote wrote: Hi Kathleen Related to the below it would be helpful if the WebTrust organization would disclose additional details on the licensed WebTrust practitioners: right now there is no data publicly available on historical WebTrust auditor licensing. We don't

Re: Request to Include Microsec e-Szigno Root CA 2017 and to EV-enable Microsec e-Szigno Root CA 2009

2020-06-04 Thread Kathleen Wilson via dev-security-policy
On 6/4/20 11:17 AM, Ben Wilson wrote: Having received no further comments, I have recommended approval of this request in bug 1445364 - Ben To clarify, Ben is recommending approval of the request to include the e-Szigno Root CA 2017

Re: Request to Include certSIGN Root CA G2 certificate

2020-06-04 Thread Ben Wilson via dev-security-policy
Having received no further comments, I have recommended approval of this request in bug 1403453 - Ben On Thu, May 28, 2020 at 12:06 PM Ben Wilson wrote: > In accordance with the CA inclusion process[1], this is a summary of the > public

Re: Request to Include Microsec e-Szigno Root CA 2017 and to EV-enable Microsec e-Szigno Root CA 2009

2020-06-04 Thread Ben Wilson via dev-security-policy
Having received no further comments, I have recommended approval of this request in bug 1445364 - Ben On Tue, Jun 2, 2020 at 1:57 PM Ben Wilson wrote: > I have now reviewed Microsec's updated CPS for OV and DV. I am not going > to hold up

CA Configuration and Operation

2020-06-04 Thread Ben Wilson via dev-security-policy
Often CA configurations and settings are complex and can be difficult to manage. We would like to remind CA operators that they need to be familiar with the configuration and operation of all aspects of CA software and ensure that they have adequate documentation and training. For example, in

RE: Verifying Auditor Qualifications

2020-06-04 Thread Arvid Vermote via dev-security-policy
Hi Kathleen Related to the below it would be helpful if the WebTrust organization would disclose additional details on the licensed WebTrust practitioners: right now there is no data publicly available on historical WebTrust auditor licensing. We don't know as of when an auditor has been