On 04/10/17 13:18, Adriano Santoni via dev-security-policy wrote:
<snip>
Are these "temporary unconstrained SubCA certificate"s publicly trusted?  That is, do they have valid signatures from your "Actalis Authentication Root CA" (https://crt.sh/?caid=935) ?
If yes, can you confirm that you have disclosed them all to the CCADB?

No. The temporary unconstrained SubCA certificate is not trusted, because it is post-processed when it still is a tbsCertificate. When it comes into existence as a signed object, it already is a technically constrained certificate. As such, it is not required to disclose it to the CCADB.

Great.  Thanks for clarifying that, Adriano.

--
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to