On 08/06/17 00:42, Jonathan Rudenberg wrote: > Yet another batch of undisclosed intermediates has shown up in CT:
Like, seriously? Every CA in our program indicated that they would disclose all their intermediates by June 30th, 2016: https://ccadb-public.secure.force.com/mozillacommunications/CACommResponsesOnlyReport?CommunicationId=a05o000000iHdtx&QuestionId=Q00004 I don't really want to switch to an intermediate whitelist because that requires coding. My patience is expiring. What CA can't keep track of the intermediates it issues? How hard is that, really? What downsides would there be, other than the obvious "some sites might break", to us just adding any such intermediate certs directly to OneCRL? Gerv _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

