WoSign and StartCom has been included as root CA in official Android builds. (https://code.google.com/p/android/issues/detail?id=71363 https://code.google.com/p/android/issues/detail?id=21632)
Apple has restrict/remove WoSign and StartCom from iOS 10.2. "Google has determined that two CAs, WoSign and StartCom, have not maintained the high standards expected of CAs and will no longer be trusted by Google Chrome, in accordance with our Root Certificate Policy. " The announcement didn't say anything about Android. Is there any plan to restrict remove WoSign and StartCom from Android? _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

