Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-12-04 Thread Kathleen Wilson via dev-security-policy
All, Section 5.1 has been added to the CCADB Policy. https://www.ccadb.org/policy#51-audit-statement-content Please let me know if you see any problems with the addition. Thanks, Kathleen ___ dev-security-policy mailing list

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-11-26 Thread Malcolm Doody via dev-security-policy
On Tuesday, 26 November 2019 16:53:21 UTC, Kathleen Wilson wrote: > The proposed section to add to the CCADB Policy (www.ccadb.org/policy) > has been updated and is here: > > https://github.com/mozilla/www.ccadb.org/issues/33#issuecomment-558714086 Typo in "Format Specifications for SHA-256

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-11-26 Thread Kathleen Wilson via dev-security-policy
All, The proposed section to add to the CCADB Policy (www.ccadb.org/policy) has been updated and is here: https://github.com/mozilla/www.ccadb.org/issues/33#issuecomment-558714086 This is the last call for feedback on it. Thanks, Kathleen ___

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-11-01 Thread Kathleen Wilson via dev-security-policy
All, The updated proposed section is here: https://github.com/mozilla/www.ccadb.org/issues/33#issuecomment-548884075 Please let me know if you have any further feedback on this proposed addition to the Common CCADB Policy. Thanks, Kathleen ___

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-31 Thread Ryan Sleevi via dev-security-policy
On Thu, Oct 31, 2019 at 7:20 PM Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > 2) Summarized: ALV tries to find a match in the Audit Letter for the > SHA256 thumbprint that is sent by CCADB. Listing thumbprints that were > out of scope within an audit

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-31 Thread Kathleen Wilson via dev-security-policy
On 10/31/19 2:51 PM, Ryan Sleevi wrote: Thanks, Kathleen. Snipped the other changes (which sound good), and a few replies inline below. On Thu, Oct 31, 2019 at 4:39 PM Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: 2. Full name of the CA that was

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-31 Thread Ryan Sleevi via dev-security-policy
Thanks, Kathleen. Snipped the other changes (which sound good), and a few replies inline below. On Thu, Oct 31, 2019 at 4:39 PM Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > >> 2. Full name of the CA that was audited; > >> 3. SHA-256 fingerprint of

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-31 Thread Kathleen Wilson via dev-security-policy
dev-security-policy@lists.mozilla.org> wrote: All, I will greatly appreciate your thoughtful and constructive feedback on the following proposal to add a section to the Common CCADB Policy, https://www.ccadb.org/policy Proposal: Add section 5.1 to the Common CCADB Policy, as follows. ~~ 5.1 Audit Sta

Re: Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-31 Thread Ryan Sleevi via dev-security-policy
> All, > > I will greatly appreciate your thoughtful and constructive feedback on > the following proposal to add a section to the Common CCADB Policy, > https://www.ccadb.org/policy > > Proposal: Add section 5.1 to the Common CCADB Policy, as follows. > ~~ > 5.1 Audit

Proposal: Add section 5.1 to the Common CCADB Policy

2019-10-30 Thread Kathleen Wilson via dev-security-policy
All, I will greatly appreciate your thoughtful and constructive feedback on the following proposal to add a section to the Common CCADB Policy, https://www.ccadb.org/policy Proposal: Add section 5.1 to the Common CCADB Policy, as follows. ~~ 5.1 Audit Statement Content CCADB uses an Audit