Re: Next Root Store Policy Update

2019-10-30 Thread Wayne Thayer via dev-security-policy
We've concluded discussions on the individual issues and can begin work to finalize the version 2.7 Root Store Policy update. Here is a redline of all the changes: https://github.com/mozilla/pkipolicy/compare/master...2.7 (click on the Files Changed tab) As noted below, two of these changes

Re: Policy 2.7 Proposal: Forbid Delegation of Email Validation for S/MIME Certificates

2019-10-30 Thread Wayne Thayer via dev-security-policy
I've opened issue #196 [1] to track Rufus' suggested clarification for a future policy update. I'll consider this issue (#175) resolved unless further comments are received. - Wayne [1] https://github.com/mozilla/pkipolicy/issues/196 On Mon, Oct 28, 2019 at 4:41 PM Wayne Thayer wrote: > On

Re: [FORGED] Firefox removes UI for site identity

2019-10-30 Thread Nick Lamb via dev-security-policy
On Tue, 29 Oct 2019 10:54:18 -0700 Paul Walsh via dev-security-policy wrote: > [PW] I agree with your conclusion. But you’re commenting on the wrong > thing. You snipped my message so much that my comment above is > without context. You snipped it in a way that a reader will think I’m > asking

Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-30 Thread Kathleen Wilson via dev-security-policy
All, I will greatly appreciate your thoughtful and constructive feedback on the following proposal to add a section to the Common CCADB Policy, https://www.ccadb.org/policy Proposal: Add section 5.1 to the Common CCADB Policy, as follows. ~~ 5.1 Audit Statement Content CCADB uses an Audit