My understanding is that the QuickInvite system doesn't distinguish the reseller from their customer in terms of access to the order.
It's not very clear from Symantec's documentation, and Tarah never got back to me in the thread about it, but I think a reseller absolutely can wait for their customer to validate control over example.com successfully and then simply substitute the CSR for one created by the reseller, to get a certificate for example.com with their chosen keys. Unlike scenarios where a web host or DNS provider obtains and installs certificates autonomously on behalf of their customer, using their existing control over the customer's domain to validate, giving a reseller this access feels like an overstep to me, and if I'm right about it I'd like to see Symantec correct this. But I suspect it doesn't breach the BRs as they're written even if it would surprise customers. _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

