Mozilla has a Root Transfer Policy which sets out our expectations regarding how roots are transferred between organizations, or what happens when one company buys another, based on a recognition that trust is not always transferable.
https://wiki.mozilla.org/CA:RootTransferPolicy It has been reasonably observed that it would be better if this policy were part of our official policy rather than a separate wiki page. So, I have attempted to take that wiki page, remove duplication and boil it down into a set of requirements to add to the existing policy. Here is a diff of the proposed changes: https://github.com/mozilla/pkipolicy/compare/issue-57 This is: https://github.com/mozilla/pkipolicy/issues/57 ------- This is a proposed update to Mozilla's root store policy for version 2.5. Please keep discussion in this group rather than on Github. Silence is consent. Policy 2.4.1 (current version): https://github.com/mozilla/pkipolicy/blob/2.4.1/rootstore/policy.md Update process: https://wiki.mozilla.org/CA:CertPolicyUpdates _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

