On 06/10/17 19:41, Doug Beattie wrote: > We could provide you with the non-SSL SHA-1 CAs and have them added to OneCRL > as long as we're sure that would not impact their use for client > authentication and secure email. Would that suffice?
Yes. File a Bugzilla bug. While we don't have a mandated timescale for this, please migrate new issuance to appropriately-constrained intermediates if you have not done so already. Gerv _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

