Re: Unrevoked/unexpired certificate with Debian Weak Key

2018-06-28 Thread Wayne Thayer via dev-security-policy
I searched through the list of certificates that Rob provided and didn't find any new issues (no valid certificates and none that had been issues since Jan 1, 2017 and not previously disclosed. I've requested an incident report from QuoVadis for the one new certificate that Hanno identified via ht

GlobalSign Root CA - R6 Inclusion Request

2018-06-28 Thread Wayne Thayer via dev-security-policy
This request is for inclusion of the GlobalSign Root CA - R6 as documented in the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1390803 This is an RSA-4096 / SHA-384 root that GlobalSign states “…will replace older, expiring roots that have smaller key sizes in the future.” * BR Self