RE: Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-11-23 Thread Steve Roylance
t; From: dev-security-policy [mailto:dev-security-policy- > bounces+steve.roylance=globalsign@lists.mozilla.org] On Behalf Of > Kathleen Wilson > Sent: 18 November 2015 19:33 > To: mozilla-dev-security-pol...@lists.mozilla.org > Subject: Re: Policy Update Proposal -- Refer to BRs for Na

Re: Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-11-18 Thread Kathleen Wilson
On 11/5/15 11:00 AM, Kathleen Wilson wrote: On 10/28/15 10:25 AM, Kathleen Wilson wrote: Therefore, this proposal is modified to simplify item #9 of the Inclusion Policy, https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ as follows: ~~ We encourage

Re: Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-11-05 Thread Kathleen Wilson
On 10/28/15 10:25 AM, Kathleen Wilson wrote: Therefore, this proposal is modified to simplify item #9 of the Inclusion Policy, https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ as follows: ~~ We encourage CAs to technically constrain all subordinate

Re: Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-10-28 Thread Kathleen Wilson
On 9/21/15 4:02 PM, Kathleen Wilson wrote: The next item on our list to discuss is: https://wiki.mozilla.org/CA:CertificatePolicyV2.3 (D2) CA/Browser Forum Baseline Requirements version 1.1.6 added a requirement regarding technically constraining subordinate CA certificates, so item #9 of the I

Re: Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-09-21 Thread Kathleen Wilson
On 9/21/15 5:01 PM, Brian Smith wrote: I think it is better to resolve whether email certificates and code signing certificates are in or out of scope for Mozilla's policy first. Good point. I will start the email trust bit discussion. We can figure that out first. Thanks, Kathleen

Re: Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-09-21 Thread Brian Smith
On Mon, Sep 21, 2015 at 4:02 PM, Kathleen Wilson wrote: > Section 7.1.5 of version 1.3 of the Baseline Requirements says: > The proposal is to simplify item #9 of the Inclusion Policy, > > https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ > by referrin

Policy Update Proposal -- Refer to BRs for Name Constraints Requirement

2015-09-21 Thread Kathleen Wilson
The next item on our list to discuss is: https://wiki.mozilla.org/CA:CertificatePolicyV2.3 (D2) CA/Browser Forum Baseline Requirements version 1.1.6 added a requirement regarding technically constraining subordinate CA certificates, so item #9 of the Inclusion Policy may refer to the BR for d