Hello: I acknowledge that QuoVadis Grid ICA2 was missing from the CCADB. The omission was human error (my own) when entering a group of issuing CAs into SalesForce. Ongoing, when new ICAs are created, the CCADB disclosure is part of our process.
For the sake of clarity, that ICA is disclosed in our Repository and included in our WebTrust audit reports. Regards, Stephen QuoVadis -----Original Message----- From: dev-security-policy [mailto:dev-security-policy-bounces+s.davidson=quovadisglobal....@lists.mozi lla.org] On Behalf Of Alex Gaynor via dev-security-policy Sent: Monday, June 5, 2017 10:30 AM To: MozPol <[email protected]> Subject: New undisclosed intermediates Happy Monday! Another week, another set of intermediate certs that have shown up in CT without having been properly disclosed: https://crt.sh/mozilla-disclosures#undisclosed There are four intermediates here, and with exception of the StartCom one, they were all issued more than a year ago. As I've expressed before, I find it baffling that this still happens. To approach this more productively, I'd be very appreciative if someone from a CA could describe how they approach disclosing intermediates, where it fits into their process, how they track progress, etc. Cheers, Alex _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

