> On May 17, 2017, at 07:24, Gervase Markham via dev-security-policy > <[email protected]> wrote: > > On 16/05/17 02:26, userwithuid wrote: >> After skimming the responses and checking a few CAs, I'm starting to >> wonder: Wouldn't it be easier to just add another mandatory field to >> the CCADB (e..g. "revocation contact"), requiring $URL or $EMAIL via >> policy and just use that to provide a public list? > > Well, such contacts are normally per CA rather than per root. I guess we > could add it on the CA's entry.
I’ve been reporting a fair amount of misissuance this week, and the responses to the Problem Reporting question in the April CA communication leave a lot to be desired. Several CAs do not have any contact details at all, and others require filling forms with captchas. I think it’d be very useful if CAs were required maintain a problem reporting email address and keep it current in the CCADB, this requirement could go in the Mozilla Root Store policy or the CCADB policy. If they want to also maintain other modes of contact, they can but no matter what an email address should be required. Jonathan _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

