Re: Policy Update: section 8 of Maintenance Policy

2015-11-09 Thread rbarnes
I'm all for modern crypto, but to be honest, these are a little far away. The OIDs for Ed25519 aren't final yet, and I'm not aware of any work on putting SHA-3 in X.509 yet. I think the right approach here is to delegate this to the BRs. --Richard On Thursday, November 5, 2015 at 3:03:05 PM

RE: CA Community in Salesforce

2015-11-09 Thread Steve Roylance
Hi Kathleen, GlobalSign would be happy to step forward as an early adopter. Steve > -Original Message- > From: dev-security-policy [mailto:dev-security-policy- > bounces+steve.roylance=globalsign@lists.mozilla.org] On Behalf Of > Kathleen Wilson > Sent: 05 November 2015 23:01 > To:

Re: CA Community in Salesforce

2015-11-09 Thread Rob Stradling
Ditto for Comodo. On 09/11/15 11:01, Steve Roylance wrote: Hi Kathleen, GlobalSign would be happy to step forward as an early adopter. Steve -Original Message- From: dev-security-policy [mailto:dev-security-policy- bounces+steve.roylance=globalsign@lists.mozilla.org] On Behalf

Re: SHA256/GCM DHE support when SHA1 support is dropped

2015-11-09 Thread Kurt Roeckx
On 2015-11-06 17:47, loths...@gmail.com wrote: https://bugzilla.mozilla.org/s... [mozilla.org] Firefox only currently supports DHE with SHA1. Are they going add support for SHA256 DHE when they disable SHA1? The dropping of SHA1 is only in certificates, not in any of the cipher suites.

Re: SECOM Request for EV Treatment

2015-11-09 Thread Kathleen Wilson
SECOM has applied to enable EV treatment for the "Security Communication RootCA2" root certificate that was included in NSS via Bugzilla Bug #527419. SECOM is a Japanese commercial CA that provides SSL and client certificates for e-Government and participates in several projects for financial