AW: Questions regarding the qualifications and competency of TUVIT

2018-11-02 Thread Wiedenhorst, Matthias via dev-security-policy
Dear all, Still posting on behalf of TÜViT. On Wed, Oct 31, 2018 at 11:43 AM Wiedenhorst, Matthias via dev-security-policy mailto:dev-security-policy@lists.mozilla.org>> wrote: · Since January 2018, T-Systems issued EV certificates with an incorrect qcStatement. T-Systems wa

AW: Questions regarding the qualifications and competency of TUVIT

2018-11-06 Thread Wiedenhorst, Matthias via dev-security-policy
Thanks for focussing the discussion on the substance and thus allowing the community moving towards a common understanding and towards defining adequate requirements for treating such kind of incidents. We are very much interested in improving the existing requirements as we have done in the

AW: Request to Include Microsec e-Szigno Root CA 2017 and to EV-enable Microsec e-Szigno Root CA 2009

2020-03-11 Thread Wiedenhorst, Matthias via dev-security-policy
Dear all, with regard to the findings listed in the different audit attestations, we would like to clarify that - all non-conformities have been resolved in a timely manner - the resolution has been audited by and proven to the certification body In addition, we would like to

AW: Request to Include Microsec e-Szigno Root CA 2017 and to EV-enable Microsec e-Szigno Root CA 2009

2020-03-13 Thread Wiedenhorst, Matthias via dev-security-policy
CA. That's not really sustainable, nor is it in line with the purpose and goal of audits themselves, at least as practiced by Mozilla since the first version of the root policy. On Wed, Mar 11, 2020 at 11:45 AM Wiedenhorst, Matthias via dev-security-policy <mailto:dev-security-policy@lists.mozil

AW: Policy 2.7.1: MRSP Issue #152: Add EV Audit exception for Policy Constraints

2020-10-19 Thread Wiedenhorst, Matthias via dev-security-policy
Hi everybody, this might not be closely connected to original topic, but allow me to comment on one issue below. Best regards Matthias > -Ursprüngliche Nachricht- > Von: dev-security-policy Im > Auftrag von Ryan Sleevi via dev-security-policy > Gesendet: Samstag, 17. Oktober 2020

AW: MRSP Issue #147 - Require EV audits for certificates capable of issuing EV certificates

2020-11-11 Thread Wiedenhorst, Matthias via dev-security-policy
Hi Ben, Hi all, sorry for the late reply. Thanks to your summary yesterday, I re-checked all the open issues and stumbled upon one question with regard to this issue that didn't came to my mind earlier. I am not sure if I am understanding correctly the desired outcome of this change. Forgive