Re: Policy 2.7.1: MRSP Issue #206: Limit re-use of domain name verification to 398 days

2021-03-19 Thread Ryan Sleevi via dev-security-policy
The S/MIME BRs are not yet a thing, while the current language covers such CAs (as a condition of Mozilla inclusion) On Fri, Mar 19, 2021 at 6:45 AM Doug Beattie via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Thanks Ben. > > > > What’s the purpose of this statement: >

Re: Policy 2.7.1: MRSP Issue #206: Limit re-use of domain name verification to 398 days

2021-03-19 Thread Ben Wilson via dev-security-policy
Hi Doug, It means the same thing as in the BRs. I am processing this change on a parallel track with adding language to the BRs (Ballot SC42) because neither change is a done deal yet. We'll leave it in for now, not to say that we won't eventually remove it in a subsequent update. Thanks, Ben On

RE: Policy 2.7.1: MRSP Issue #206: Limit re-use of domain name verification to 398 days

2021-03-19 Thread Doug Beattie via dev-security-policy
Thanks Ben. What’s the purpose of this statement: 5. verify that all of the information that is included in server certificates remains current and correct at intervals of 825 days or less; The BRs limit data reuse to 825 days since March 2018 so I don’t think this adds anything. If it