Thank you for clarification! But you would support the overall insight: 
currently it is not clear from the BRGs or the Mozilla Root Store Policy if 
this is a misissuance or not and we should clarify it?

/Rufus

From: [email protected] <[email protected]> On 
Behalf Of Ryan Sleevi
Sent: Wednesday, 4 August 2021 17:18
To: Buschart, Rufus (IT IN COR TSQ-1) <[email protected]>
Cc: [email protected]
Subject: Re: Your opinion on misissuance under name constrained ICAs



On Wed, Aug 4, 2021 at 5:46 AM Buschart, Rufus 
<[email protected]<mailto:[email protected]>> wrote:
Ryan S: 
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XsVpyOGlagE/m/MIUVYrGZAwAJ<https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fa%2Fmozilla.org%2Fg%2Fdev-security-policy%2Fc%2FXsVpyOGlagE%2Fm%2FMIUVYrGZAwAJ&data=04%7C01%7Crufus.buschart%40siemens.com%7C5fe51d253c6d42e21e3008d9575b0956%7C38ae3bcd95794fd4addab42e1495d55a%7C1%7C0%7C637636870776021482%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=1g0aNeQMSbUuwNKRy8rJ9E6O33JkdhaIejTHEC%2B6F14%3D&reserved=0>

I realize in posing the “thought experiment” it may not have been clear where I 
personally stand: I would prefer CAs consistently treat it as misissuance, even 
if they feel it is ambiguous or disagree, and believe _this specific example_ 
should be considered misissuance, even if domain validation was properly 
performed.
--
You received this message because you are subscribed to the Google Groups 
"[email protected]<mailto:[email protected]>" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CAErg%3DHF_sUOTeea1Pb9T3VHBuAox%2B6iBijaC180wnMCNwYAUYA%40mail.gmail.com<https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fa%2Fmozilla.org%2Fd%2Fmsgid%2Fdev-security-policy%2FCAErg%253DHF_sUOTeea1Pb9T3VHBuAox%252B6iBijaC180wnMCNwYAUYA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=04%7C01%7Crufus.buschart%40siemens.com%7C5fe51d253c6d42e21e3008d9575b0956%7C38ae3bcd95794fd4addab42e1495d55a%7C1%7C0%7C637636870776031437%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=S4W6JCCjtWxiU4sywacZSPJpaoyhOTYfQBu7x7Bm13I%3D&reserved=0>.

-- 
You received this message because you are subscribed to the Google Groups 
"[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/AM8PR10MB4305D797295978276CBA92419EF19%40AM8PR10MB4305.EURPRD10.PROD.OUTLOOK.COM.

Reply via email to