ramirommunoz--- via dev-security-policy <[email protected]> 
writes:

>1) How your CA first became aware of the problem
>Affected certificates
>Serial number:0d dates:15 Nov-2007 to 8-Nov-2032 Name:AC Camerfirma Express 
>corporate Server(1)
>Serial number:0d dates:23 Feb-2010 to 20-Feb-2022 Name:AC Camerfirma AAPP(2).
>
>We were aware some time later of Febr 2010 after issuing the (2) SubCA when
>we already had issued valid certificates.

So just to confirm this, the CA has known about these invalid certificates for
SEVEN YEARS and is only now taking action over them?

Do the BR's contain any text on timeliness of action, or is it like the Swiss
plan to shut down their reactors?  (German plan: We've voted to shut them
down, here's the schedule.  Swiss plan: We've voted to shut them down, and now
we've finished voting on shutting them down).

Peter.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to