Thank you for clarification! But you would support the overall insight: currently it is not clear from the BRGs or the Mozilla Root Store Policy if this is a misissuance or not and we should clarify it?
/Rufus From: [email protected] <[email protected]> On Behalf Of Ryan Sleevi Sent: Wednesday, 4 August 2021 17:18 To: Buschart, Rufus (IT IN COR TSQ-1) <[email protected]> Cc: [email protected] Subject: Re: Your opinion on misissuance under name constrained ICAs On Wed, Aug 4, 2021 at 5:46 AM Buschart, Rufus <[email protected]<mailto:[email protected]>> wrote: Ryan S: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XsVpyOGlagE/m/MIUVYrGZAwAJ<https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fa%2Fmozilla.org%2Fg%2Fdev-security-policy%2Fc%2FXsVpyOGlagE%2Fm%2FMIUVYrGZAwAJ&data=04%7C01%7Crufus.buschart%40siemens.com%7C5fe51d253c6d42e21e3008d9575b0956%7C38ae3bcd95794fd4addab42e1495d55a%7C1%7C0%7C637636870776021482%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=1g0aNeQMSbUuwNKRy8rJ9E6O33JkdhaIejTHEC%2B6F14%3D&reserved=0> I realize in posing the “thought experiment” it may not have been clear where I personally stand: I would prefer CAs consistently treat it as misissuance, even if they feel it is ambiguous or disagree, and believe _this specific example_ should be considered misissuance, even if domain validation was properly performed. -- You received this message because you are subscribed to the Google Groups "[email protected]<mailto:[email protected]>" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CAErg%3DHF_sUOTeea1Pb9T3VHBuAox%2B6iBijaC180wnMCNwYAUYA%40mail.gmail.com<https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fa%2Fmozilla.org%2Fd%2Fmsgid%2Fdev-security-policy%2FCAErg%253DHF_sUOTeea1Pb9T3VHBuAox%252B6iBijaC180wnMCNwYAUYA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=04%7C01%7Crufus.buschart%40siemens.com%7C5fe51d253c6d42e21e3008d9575b0956%7C38ae3bcd95794fd4addab42e1495d55a%7C1%7C0%7C637636870776031437%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=S4W6JCCjtWxiU4sywacZSPJpaoyhOTYfQBu7x7Bm13I%3D&reserved=0>. -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/AM8PR10MB4305D797295978276CBA92419EF19%40AM8PR10MB4305.EURPRD10.PROD.OUTLOOK.COM.
