On 06/07/17 16:31, Doug Beattie wrote: > Moving to a new CA within 6 months is certain reasonable, but having > enterprise customers also replace all certificates so the CA can be revoked > within 6 months might be a bit short, especially since several of those > months are over the holidays. Would you consider an approach were the CAs > MUST not issue new certificates after 15 November (4 months) and the CAs > SHALL be revoked no later than 15 April (9 months)?
Yeah, OK. A bit late for this feedback :-), but I'll make a fix when I get back. Can you file a bug, please? https://github.com/mozilla/pkipolicy/issues Gerv _______________________________________________ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy