New Sub CAs under the DigiCert RSA and ECC Transition Roots

2017-11-10 Thread Ben Wilson via dev-security-policy
In the spirit of full transparency and in attempt to comply to the extent we can with Mozilla policy, on Thursday, Nov. 2, we created several sub CAs under two new "transition" roots (yet to be submitted as roots). These sub CAs haven't been uploaded yet to the CCADB because no instances of the

Re: Acquisition policy (was: Francisco Partners acquires Comodo certificate authority business)

2017-11-10 Thread Wayne Thayer via dev-security-policy
On Thu, Nov 9, 2017 at 1:25 PM, Peter Kurrasch via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > There's always a risk that a CA owner will create a security nightmare > when we aren't looking, probationary period or not. In theory regular > audits help to prevent it, but