Re: Subscriber Certificate Structure

2018-03-15 Thread Ryan Sleevi via dev-security-policy
On Thu, Mar 15, 2018 at 7:37 AM YairE via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hi Ryan, thanks for your reply > > I'm afraid I didn't make my question clear enough or that i was missing > something in the link you sent to me > > what I am asking is this: > in a sub

Re: Subscriber Certificate Structure

2018-03-15 Thread YairE via dev-security-policy
Hi Ryan, thanks for your reply I'm afraid I didn't make my question clear enough or that i was missing something in the link you sent to me what I am asking is this: in a subscriber certificate under subject every CA i saw puts a CN=domain name what I understand from the BR is that the best stru

Re: Subscriber Certificate Structure

2018-03-08 Thread Ryan Sleevi via dev-security-policy
s it clearly states that the > SubjectCN is deprecated, so I learn from that that the best subscriber > certificate structure would simply not include this field > I did a small survey and I couldn’t find not even one certificate without > the SubjectCN - so my question is: > should w

Subscriber Certificate Structure

2018-03-08 Thread YairE via dev-security-policy
Hi everyone, I tried to dive into the best certificate structure and there are two things that bother me: In both the CA\B F BR and the EV guidelines it clearly states that the SubjectCN is deprecated, so I learn from that that the best subscriber certificate structure would simply not