Hi,

On Thu, 27 Jun 2024 14:19:40 -0600
"'Kurt Seifried' via CCADB Public" <[email protected]> wrote:

> Question: what about CN = Entrust Verified Mark Root Certification
> Authority - VMCR1 which is used for BIMI logos for example and
> supported in Gmail? Will Gmail be removing support for Entrust based
> VMC certificates and thus BIMI logos done via Entrust?

In this context, possibly interesting: I had recently discovered that
many VMCs issued by Entrust were not compliant with the BIMI SVG
profile. I had made that public on the IETF BIMI list:
https://mailarchive.ietf.org/arch/msg/bimi/xzYRH72V2HE9xeUfXK_zUgYSI7k/

Entrust handled the revocation reasonably well, but of course,
it raises questions how this could happen in the first place.
(I was more disappointed with Google's/GMail's reaction, or rather,
non-reaction)

-- 
Hanno Böck - Independent security researcher
https://itsec.hboeck.de/

-- 
You received this message because you are subscribed to the Google Groups 
"CCADB Public" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/ccadb.org/d/msgid/public/20240705102429.4714c83d%40computer.

Reply via email to