Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Ramiro Muñoz via dev-security-policy
El martes, 19 de enero de 2021 a las 14:32:19 UTC+1, paul.leo@gmail.com escribió: > On Tuesday, January 19, 2021 at 11:01:15 AM UTC+1, Ramiro Muñoz wrote: > > > Finally, I’d like to ask you, based on which article of Mozilla Root Store > > Policy, you are sentencing a removal from the

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread paul.leo....--- via dev-security-policy
On Tuesday, January 19, 2021 at 11:01:15 AM UTC+1, Ramiro Muñoz wrote: > Finally, I’d like to ask you, based on which article of Mozilla Root Store > Policy, you are sentencing a removal from the Mozilla store. Oh, I know this one: It is in the Mozilla Root Store Policy, 7.3: "Mozilla MAY, at

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Kurt Roeckx via dev-security-policy
On 2021-01-19 11:02, Ramiro Muñoz wrote: El martes, 19 de enero de 2021 a las 0:49:42 UTC+1, Matt Palmer escribió: On Sun, Jan 17, 2021 at 12:51:29AM -0800, Ramiro Muñoz via dev-security-policy wrote: We don’t ask the community to disregard the data, on the contrary we ask the community to

Re: Audit Reminder Email Summary

2021-01-19 Thread Kathleen Wilson via dev-security-policy
Forwarded Message Subject: Summary of January 2021 Audit Reminder Emails Date: Tue, 19 Jan 2021 20:00:30 + (GMT) Mozilla: Audit Reminder CA Owner: Krajowa Izba Rozliczeniowa S.A. (KIR) Root Certificates: SZAFIR ROOT CA2 Standard Audit:

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Andrew Ayer via dev-security-policy
On Sun, 17 Jan 2021 00:51:29 -0800 (PST) Ramiro Mu__oz via dev-security-policy wrote: > Some certificates may have been syntactically > incorrect due to misinterpretation, but we have never compromised any > vetting, identification or information validation. This is false, as shown by incidents

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Paul Kehrer via dev-security-policy
On Tue, Jan 19, 2021 at 6:37 PM Jonathan Rudenberg via dev-security-policy wrote: > > On Tue, Jan 19, 2021, at 12:01, Andrew Ayer via dev-security-policy wrote: > > Camerfirma was warned in 2018 that trust in their CA was in jeopardy, > > yet compliance problems continued. There is no reason to

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Jonathan Rudenberg via dev-security-policy
On Tue, Jan 19, 2021, at 12:01, Andrew Ayer via dev-security-policy wrote: > Camerfirma was warned in 2018 that trust in their CA was in jeopardy, > yet compliance problems continued. There is no reason to believe > Camerfirma will improve, and there are many indications that they won't. >

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Matt Palmer via dev-security-policy
On Tue, Jan 19, 2021 at 07:28:17AM -0800, Ramiro Muñoz via dev-security-policy wrote: > Camerfirma is not the member with the highest number of > incidents nor the member with the most severe ones. No, but Camerfirma's got a pretty shocking history of poor incident response, over an extended

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Ramiro Muñoz via dev-security-policy
El martes, 19 de enero de 2021 a las 0:49:42 UTC+1, Matt Palmer escribió: > On Sun, Jan 17, 2021 at 12:51:29AM -0800, Ramiro Muñoz via > dev-security-policy wrote: > > We don’t ask the community to disregard the data, on the contrary we ask > > the community to analyze the data thoroughly

Re: Summary of Camerfirma's Compliance Issues

2021-01-19 Thread Ramiro Muñoz via dev-security-policy
El martes, 19 de enero de 2021 a las 0:49:42 UTC+1, Matt Palmer escribió: > On Sun, Jan 17, 2021 at 12:51:29AM -0800, Ramiro Muñoz via > dev-security-policy wrote: > > We don’t ask the community to disregard the data, on the contrary we ask > > the community to analyze the data thoroughly