On 01/05/17 07:52, Percy wrote: > It seems that StartCom continues to sell untrusted certs. Neither their home > page https://www.startcomca.com/ nor their announcement page > https://www.startcomca.com/index/news mentions that those certs are not > trusted.
Why is this something that Mozilla should be concerned with? "Selling untrusted certs" is not a crime, or a violation of any standard. Mozilla is not the global authority on what certificates may be issued. If StartCom are providing certificates which do not do what their customers expect, I'm sure those customers will let them know about it soon enough. Gerv _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

