Re: Policy 2.7.1: MRSP Issue #211: Align OCSP requirements in Mozilla's policy with the BRs

2020-12-21 Thread Wayne Thayer via dev-security-policy
On Thu, Dec 17, 2020 at 10:32 AM Aaron Gable via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > One potential option (5) would be to go even further than (2), and remove > the OCSP paragraph from the MRSP§6 entirely. Given that MRSP§2.3 says "CA > operations relating to

Re: Policy 2.7.1: MRSP Issue #211: Align OCSP requirements in Mozilla's policy with the BRs

2020-12-17 Thread Aaron Gable via dev-security-policy
As an individual, I'd prefer that the Mozilla root program requirements incorporate the entirety of BR§4.9.10 by reference, i.e. I prefer option (2). I prefer (2) over (1) because it makes it easier to "diff" the respective documents. Given that MRSP§6 appears to be strictly looser than