Re: New problematic practice

2013-11-29 Thread Ralph Holz (TUM)
Hi, ===Backdating the notBefore date=== Certificates do not contain an issue timestamp, so it is not possible to be certain when they were issued. The notBefore date is the start of the certificate's validity range, and is set by the CA. It should be a reasonable reflection of the date on

Re: New problematic practice

2013-11-29 Thread Brian Smith
On Fri, Nov 29, 2013 at 1:20 AM, Gervase Markham g...@mozilla.org wrote: Comments? I suggest you propose it as a change to the baseline requirements. Cheers, Brian -- Mozilla Networking/Crypto/Security (Necko/NSS/PSM) ___ dev-security-policy mailing