The timing and content of any announcement is undoubtedly complicated, caused, in no small part, by legitimate needs for confidentiality against the goals of transparency. I have every reason to trust in the good judgment of Gerv and Kathleen in navigating that path with the interests of this community in mind. If there is more they are able to say on this matter, I hope that they will; if not, I will understand.

That said, I ‎hope someone will indeed say more about the reporting in these articles. There are 2 issues in particular that I think would be good to address at this time. The first is the use of the past tense (e.g. "has acquired") regarding the reported transaction. How much of the acquisition process has, in fact, transpired--if anything?

The second is ‎the meager explanation of what has transpired or is expected to transpire--again, if anything. Based on my understanding, there is (or will be) a change of legal ownership and leadership. Accordingly, is a review of the new ownership warranted? Bringing together a CA with a Deep Packet Inspection business certainly is...uncomfortable.

It is my sincere hope that someone will come forward and provide some clarity, even if just to say this is fake news.


From: Ryan Sleevi
Sent: Tuesday, October 31, 2017 2:59 PM‎
To: Peter Kurrasch
Reply To: r...@sleevi.com
Cc: mozilla-dev-security-policy
Subject: Re: Francisco Partners acquires Comodo certificate authority business


On Tue, Oct 31, 2017 at 3:44 PM, Peter Kurrasch via dev-security-policy <dev-security-policy@lists.mozilla.org> wrote:
Both articles are long on names, short on dates. I don't fault the authors for that but it is troubling that better information wasn't made available to them.

When can we expect a proper announcement in this forum? I would expect any such announcement to provide details on the skills and experience that this new leadership team has in running a CA. ‎For example, are they aware of section 8 of the Mozilla Root Store Policy?

Such announcements are not part of the Mozilla Policy expectations. Could you clarify why you expect such an announcement? 







_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to