Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-23 Thread Ben Wilson via dev-security-policy
Dear Andrew, The purpose of my email was to alert the Mozilla community of a COVID-19 concern as it arose and to start/continue a dialogue on these COVID-19 matters. I was hoping to get some general feedback to help guide our COVID-19 policy. I appreciate the feedback so far. As mentioned in

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-23 Thread westmail24--- via dev-security-policy
Hello Ben, What CA you present here? Andrew. ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-20 Thread Eric Mill via dev-security-policy
On Sun, Apr 19, 2020 at 2:41 PM Ben Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Dear MDSP community, > > As you are aware from past discussions on this list, there has been a > concern about the impact of COVID-19 on CA operations. COVID-19 continues > to

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-20 Thread Roland Shoemaker via dev-security-policy
(Posting in a personal capacity) I think everyone so far has made valid points about why this is unexpected, and a dangerous precedent to set going forward. That said I'd like to reiterate that this feels like rewarding undesirable behavior. The CAs that will benefit from an exemption,

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-20 Thread Andrew Ayer via dev-security-policy
Like others, I am concerned with the lack of transparency around this proposal. Many of the options under consideration would be a departure from Mozilla's no exceptions policy, which could have serious consequences that undermine trust in Mozilla's root program. This ought to require compelling

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-19 Thread Filippo Valsorda via dev-security-policy
I am also personally surprised and confused by this announcement. I could imagine of course incident reports being handled with more leniency when the details reveal that the health emergency contributed to the issue. I thought that was the point of the no exceptions policy, to push the CAs to

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-19 Thread Jonathan Rudenberg via dev-security-policy
On Sun, Apr 19, 2020, at 17:41, Ben Wilson via dev-security-policy wrote: > Recently at least one CA has expressed concern about Action 3 of Mozilla's > January 2020 CA Communication [3] and enforcement of Section 5.2 of > Mozilla’s Root Store Policy Please have the CA post complete details of

Re: COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-19 Thread Ryan Sleevi via dev-security-policy
On Sun, Apr 19, 2020 at 5:41 PM Ben Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Recently at least one CA has expressed concern about Action 3 of Mozilla's > January 2020 CA Communication [3] What CA? Transparency seems essential here, for the community, for

COVID-19 Policy (especially EKU Deadline of 1-July-2020)

2020-04-19 Thread Ben Wilson via dev-security-policy
Dear MDSP community, As you are aware from past discussions on this list, there has been a concern about the impact of COVID-19 on CA operations. COVID-19 continues to impact certain areas of the world more severely than others. For example, there has been a recent resurgence of COVID-19 in