My understanding is that the QuickInvite system doesn't distinguish the 
reseller from their customer in terms of access to the order.

It's not very clear from Symantec's documentation, and Tarah never got back to 
me in the thread about it, but I think a reseller absolutely can wait for their 
customer to validate control over example.com successfully and then simply 
substitute the CSR for one created by the reseller, to get a certificate for 
example.com with their chosen keys.

Unlike scenarios where a web host or DNS provider obtains and installs 
certificates autonomously on behalf of their customer, using their existing 
control over the customer's domain to validate, giving a reseller this access 
feels like an overstep to me, and if I'm right about it I'd like to see 
Symantec correct this. But I suspect it doesn't breach the BRs as they're 
written even if it would surprise customers.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to