Re: MRSP 2.9: Issue #250: Clarify MRSP 5.3.2 to expressly include revoked CA certificates

2023-08-18 Thread Ben Wilson
All, Here is the currently proposed language for the first paragraph of MRSP section 5.3.2: The operator of a CA certificate included in Mozilla’s root store MUST publicly disclose in the CCADB all CA certificates it issues that chain up to that CA certificate trusted in Mozilla’s root store that

MRSP 2.9: Issue #250: Clarify MRSP 5.3.2 to expressly include revoked CA certificates

2023-07-05 Thread Ben Wilson
All, This email opens up discussion of our proposed resolution of GitHub Issue #250 . Currently, MRSP section 5.3.2 (Intermediate CA Certificates must be publicly disclosed and audited) requires that all types of intermediate CAs capable of