Re: Only accepting 2048 bit or better certificates

2014-06-25 Thread Eddy Nigg
On 06/21/2014 07:15 PM, Kurt Roeckx wrote: But I would like to start enforcing the 2048 bit as soon as possible. Do we have some criteria for at which point we're willing to break compatibility? I'm in favor of enforcing it which will help reduce even mistakenly issued certificates with

Re: Only accepting 2048 bit or better certificates

2014-06-23 Thread Gervase Markham
On 21/06/14 17:15, Kurt Roeckx wrote: There are still a few new certificates generated with 1024 bits. I've been filing bugs about those and there were only a few so far this month. Thank you for doing this work; it really is appreciated. Gerv

Re: Only accepting 2048 bit or better certificates

2014-06-22 Thread Kurt Roeckx
On Sat, Jun 21, 2014 at 05:37:20PM -0700, David E. Ross wrote: There are still a few new certificates generated with 1024 bits. I've been filing bugs about those and there were only a few so far this month. Maybe we can set a date from which we won't be accepting certificates with a

RE: Only accepting 2048 bit or better certificates

2014-06-21 Thread Jeremy Rowley
I think getting them revoked would be the first step. If you make the data available about which CAs still have 1024 bit certs or lower, we could email the CAs and find out what is going on. Jeremy -Original Message- From: dev-security-policy

Re: Only accepting 2048 bit or better certificates

2014-06-21 Thread David E. Ross
On 6/21/2014 11:37 AM, Jeremy Rowley wrote: I think getting them revoked would be the first step. If you make the data available about which CAs still have 1024 bit certs or lower, we could email the CAs and find out what is going on. Jeremy -Original Message- From: