Re: Auditing of CA facilities in lockdown because of an environmental disaster/pandemic

2020-02-20 Thread Ryan Sleevi via dev-security-policy
On Thu, Feb 20, 2020 at 4:58 PM Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > We will continue to follow our standard process to adjudicate the issue > regarding failures to provide CA audit statements [1] and we will work > with the impacted CAs

Re: Auditing of CA facilities in lockdown because of an environmental disaster/pandemic

2020-02-20 Thread Kathleen Wilson via dev-security-policy
All, First, I would like to add a personal note that I am truly sorry about the many people, families, and colleagues that are being impacted by the Coronavirus. This is a heartbreaking situation. At Mozilla, our responsibility lies in ensuring people's security and privacy as they navigate

Re: Auditing of CA facilities in lockdown because of an environmental disaster/pandemic

2020-02-20 Thread Ryan Sleevi via dev-security-policy
What would/should be the expected response if a natural disaster/act of God happened and the security of the key material could not be assured by an independent third party? For example, an earthquake, typhoon, or military coup disrupting travel to location(s) with the key material? Similarly,