On 20/04/2017 15:46, Gervase Markham wrote:
Section 6 of the Root Store Policy gives a list of reasons for
revocation, as do the BRs. The BRs list is somewhat more comprehensive
than ours; ours may be an earlier version of theirs.
We should remove the duplication by referencing the list in the BRs and
add any extra ones we might need, bearing in mind that the BRs are only
for TLS/SSL certificates, and our policy also covers S/MIME.
Our existing list rather assumes SSL certificates (e.g. bullet 5). I
can't think of any extra ones to add above and beyond those listed.
So, proposed new text:
"CAs MUST revoke Certificates that they have issued upon the
occurrence of any event listed in the appropriate subsection of section
4.9.1 of the Baseline Requirements (for email certificates, not
including those events specific to the inclusion of Domain Names)."
Note that some reasons applicable to domain names would be equally
applicable to the domain name part of e-mail addresses. For example,
if Company X looses "ownership" of domain example.com, this should have
equal effect on TLS certificates for www.example.com and e-mail
certificates for [email protected].
Extend this as applicable to other domain related situations.
Are there any circumstances under which Mozilla should require
revocation which are not among those listed in the BRs?
How about this: If the operator/"owner" of the e-mail domain informs
the CA that the certificate holder has lost its rights to the specific
e-mail address under that domain?
This is: https://github.com/mozilla/pkipolicy/issues/14
Enjoy
Jakob
--
Jakob Bohm, CIO, Partner, WiseMo A/S. https://www.wisemo.com
Transformervej 29, 2860 Søborg, Denmark. Direct +45 31 13 16 10
This public discussion message is non-binding and may contain errors.
WiseMo - Remote Service Management for PCs, Phones and Embedded
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy