Re: For CAs: What makes a Good Incident Response?

2019-08-22 Thread Dean C via dev-security-policy
On Wednesday, August 21, 2019 at 3:43:21 PM UTC-4, Ryan Sleevi wrote: > (Apologies if this triple or quadruple posts. There appears to be some > hiccups somewhere along the line between my mail server and the m.d.s.p. > mail server and the Google Groups reflector) > > I've recently shared some

Re: New SHA-1 certificates issued in 2016

2016-11-03 Thread c
On Saturday, October 29, 2016 at 12:02:54 PM UTC-5, Gervase Markham wrote: > The scope of the BRs is debateable. These certs are clearly in scope for > Mozilla policy, as they chain up to trusted roots; however Mozilla > policy does not (yet) ban SHA-1 issuance other than via the BRs. This > may