Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-07 Thread 'Amir Omidi (aaomidi)' via dev-security-policy@mozilla.org
I just wanted to point out that e-commerce's communication is still very-very delayed: https://bugzilla.mozilla.org/show_bug.cgi?id=1893546#c1, https://bugzilla.mozilla.org/show_bug.cgi?id=1862004#c9 I think e-commerce is getting into the territory where we should really consider if they're a

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-03 Thread Wayne
Hi Andrew, I was looking at https://globaltrust.eu/certificate-policy/ and the 'GLOBALTRUST 2015 SERVER OV 2' entry which includes a list of test servers. I can see there is a different list of test servers listed higher on the page, and 2020 functions correctly, but 2015 has the same issue

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-03 Thread Andrew Ayer
Hi Wayne, On Fri, 3 May 2024 04:29:15 -0700 (PDT) Wayne wrote: > They don't list valid/expired/revoked domains for all of their > sub-CAs CAs are only required to provide one set of test websites per root, not for every sub-CA. > and even the ones they do are running on the same wildcard >

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-03 Thread Wayne
> > -- > *From:* dev-secur...@mozilla.org on behalf of > Wayne > *Sent:* 03 May 2024 12:29 > *To:* dev-secur...@mozilla.org > *Cc:* Roman Fischer > > *Subject:* Re: Public Discussion of Acquisition of e-commerce monitoring > GmbH by AU

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-03 Thread 'Rob Stradling' via dev-security-policy@mozilla.org
mozilla.org on behalf of Wayne Sent: 03 May 2024 12:29 To: dev-security-policy@mozilla.org Cc: Roman Fischer Subject: Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH CAUTION: This email originated from outside of the org

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-03 Thread Wayne
t; > > > *From:* 'Ben Wilson' via dev-secur...@mozilla.org < > dev-secur...@mozilla.org> > *Sent:* Dienstag, 30. April 2024 23:15 > *To:* Amir Omidi (aaomidi) > *Cc:* dev-secur...@mozilla.org; regist...@e-monitoring.at < > regist...@e-monitoring.at> > *S

RE: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-05-03 Thread Roman Fischer
: Dienstag, 30. April 2024 23:15 To: Amir Omidi (aaomidi) Cc: dev-security-policy@mozilla.org; regist...@e-monitoring.at Subject: Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH Hi Amir, Here is a quick update on this issue

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-04-30 Thread 'Amir Omidi (aaomidi)' via dev-security-policy@mozilla.org
Considering this is open: https://bugzilla.mozilla.org/show_bug.cgi?id=1893546 I do think that such a temporary grant does not make sense. e-commerce has so far not showed themselves to be a good steward of public trust. What are the implications of e-commerce being distrusted by Mozilla,

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-04-30 Thread 'Ben Wilson' via dev-security-policy@mozilla.org
Hi Amir, Here is a quick update on this issue, while I continue working on a summary of the discussion concerning the acquisition of e-commerce monitoring by AUSTRIA CARD. Since June 1, 2022, section 3.2 of the Mozilla Root Store Policy (MRSP) has required that ETSI auditors be members of the

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-04-26 Thread 'Amir Omidi (aaomidi)' via dev-security-policy@mozilla.org
Did you ever hear from them? On Tuesday, March 5, 2024 at 11:18:13 AM UTC-5 Ben Wilson wrote: > All, > March 1 was the scheduled end of public discussion on this matter. > However, I have one unresolved question that I have presented to the CA > operator and its audit firm regarding ACAB'c

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-03-05 Thread Ben Wilson
All, March 1 was the scheduled end of public discussion on this matter. However, I have one unresolved question that I have presented to the CA operator and its audit firm regarding ACAB'c membership (see MRSP section 3.2). As soon as I hear back on that question, I'll provide a summary of the

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-23 Thread e-commerce monitoring
*Preface* The only thing that changed is the ownership, and the ownership is represented by the new management. This only formal change has already been notified to the authorities and approved and registered. The rest remains unchanged. e-commerce monitoring GmbH fulfills different trust

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-08 Thread e-commerce monitoring
Dear All, e-commerce monitoring GmbH is now 100% subsidiary of AUSTRIA CARD-Plastikkarten und Ausweissysteme Gesellschaft m.b.H., which is classified as “große Kapitalgesellschaft” (large corporation) and therefore needs to comply with all regulations of the Austrian GmbHG (limited

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-06 Thread Ben Wilson
Hi Aaron, On Tue, Feb 6, 2024 at 3:00 PM Aaron Gable wrote: > e-commerce monitoring GmbH currently has multiple open bugzilla tickets > which have not had any updates from their staff in multiple months: > - https://bugzilla.mozilla.org/show_bug.cgi?id=1815534 > -

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-06 Thread 'Aaron Gable' via dev-security-policy@mozilla.org
e-commerce monitoring GmbH currently has multiple open bugzilla tickets which have not had any updates from their staff in multiple months: - https://bugzilla.mozilla.org/show_bug.cgi?id=1815534 - https://bugzilla.mozilla.org/show_bug.cgi?id=1862004 Does the behavior of the CA being acquired

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-02 Thread Ben Wilson
Dear Suchan, You make a valid point. However, in this case, I wasn't sure how other root stores would be handling this. They may have their own processes. Also, the distribution on this list is almost 3x greater than on the CCADB public list, so I decided to post the discussion here. If the other

Re: Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-02 Thread Suchan Seo
While not have knowledge to comment about acquire itself, doesn't this more fit to ccadb mailing list? I thought root store policy about individual root was moved to there 2024년 2월 3일 토요일 오전 1시 45분 19초 UTC+9에 Ben Wilson님이 작성: > All, > > Recently we were advised that e-commerce monitoring GmbH

Public Discussion of Acquisition of e-commerce monitoring GmbH by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH

2024-02-02 Thread Ben Wilson
All, Recently we were advised that e-commerce monitoring GmbH is being acquired by AUSTRIA CARD-Plastikkarten und Ausweissysteme GmbH. e-commerce monitoring operates the GLOBALTRUST 2020 root CA that is included in the Mozilla root store. They have advised us of the following: There are no