On 04/10/17 13:18, Adriano Santoni via dev-security-policy wrote:
<snip>
Are these "temporary unconstrained SubCA certificate"s publicly
trusted? That is, do they have valid signatures from your "Actalis
Authentication Root CA" (https://crt.sh/?caid=935) ?
If yes, can you confirm that you have disclosed them all to the CCADB?
No. The temporary unconstrained SubCA certificate is not trusted,
because it is post-processed when it still is a tbsCertificate. When it
comes into existence as a signed object, it already is a technically
constrained certificate. As such, it is not required to disclose it to
the CCADB.
Great. Thanks for clarifying that, Adriano.
--
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy