RE: StartCom communication

2017-09-04 Thread Inigo Barreira via dev-security-policy
Hi Andrew, Thank you for your questions/suggestions. Let me answer 1.- We removed the ability to the CA administrator as a role to issue certificates, independently who´s assigned to that role. In the explanation I tried to detail exactly what happened and who did it (not to blame on them) and

Re: StartCom communication

2017-09-04 Thread Andrew Ayer via dev-security-policy
On Mon, 4 Sep 2017 12:10:19 + Inigo Barreira via dev-security-policy wrote: > [...] > > a. Test certificates > > It__s been detailed in bugzilla #1369359. There__s an attachment with a > detailed explanation what happened, when, who, what was done to >

Re: TBSCertificate / Certificate Linting APIs

2017-09-04 Thread Rob Stradling via dev-security-policy
Anyone who's using or planning to use these crt.sh APIs might like to know that I've enhanced them to also run the ZLint certificate linter (from https://github.com/zmap/zlint). On 18/08/17 17:39, Rob Stradling via dev-security-policy wrote: In response to the many BR compliance issues [1]

StartCom communication

2017-09-04 Thread Inigo Barreira via dev-security-policy
Hi all, I´ve realized that there has not been a good communication path to announce all the tasks and actions performed by StartCom during this time and this email will try to remediate it. I´d also like to ask you for some feedback, comments and/or suggestions on how to improve. I think we´ve

RE: Violations of Baseline Requirements 4.9.10

2017-09-04 Thread Peter Miškovič via dev-security-policy
Hi Paul, Problem with OCSP response for RootCA (CA Disig Root R1 and CA Disig Root R2) was fixed on Thursday August 31, 2017. Regards Peter Miskovic From: Paul Kehrer [mailto:paul.l.keh...@gmail.com] Sent: Tuesday, August 29, 2017 2:48 PM To: