Re: Chunghwa Telecom eCA Root Inclusion Request

2018-06-05 Thread lcchen.cissp--- via dev-security-policy
lcchen...@gmail.com於 2018年6月5日星期二 UTC+8下午5時22分40秒寫道: > > 1. We plan to modify the format of this type of certificate. The new > certificate format will contain an EKU that excludes anyPolicy, > emailProtection and serverAuth; besides, there will be no SubjectAltName > anymore. In other words,

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-06-05 Thread lcchen.cissp--- via dev-security-policy
Wayne Thayer於 2018年5月19日星期六 UTC+8上午8時13分15秒寫道: > This request is for inclusion of the Chunghwa Telecom eCA as documented in > the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1341604 > ==Bad== > * A large number of certificates have been misissued from the “Public >

Re: OISTE WISeKey Global Root GC CA Root Inclusion Request

2018-06-05 Thread Ryan Sleevi via dev-security-policy
Hi Pedro, I think the previous replies tried to indicate that I will not be available to review your feedback at all this week. On Mon, Jun 4, 2018 at 9:18 AM, Pedro Fuentes via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Kind reminder. > Thanks! > >

Re: Namecheap refused to revoke certificate despite domain owner changed

2018-06-05 Thread Richard S. Leung via dev-security-policy
Howdy, Thank you all for the discussions around this topic, just a quick update on the situation. Following Jakob's advice, I have notified both Comodo and Namecheap that under BR, they needed to revoke that specific certificate I brought up. So far, Comodo's SSL Abuse Dept. (