Re: Audit Letter Validation (ALV) on intermediate certs in CCADB

2019-10-29 Thread Kathleen Wilson via dev-security-policy
CAs, Here's additional information based on questions I've received about what to do if you determine that an intermediate certificate is not listed in an audit statement that it should have been in. When an intermediate certificate is not listed in all of the necessary audit reports, it is

Re: [FORGED] Firefox removes UI for site identity

2019-10-29 Thread Paul Walsh via dev-security-policy
> On Oct 29, 2019, at 12:03 PM, James Burton wrote: > > Correction: > > This isn't throwing insults at each other, it's about improving web security > and not directing people to the wrong conclusions which the CA Security > Council has done which is bad for the improvement of web security.

Re: [FORGED] Firefox removes UI for site identity

2019-10-29 Thread Paul Walsh via dev-security-policy
> On Oct 29, 2019, at 11:56 AM, James Burton wrote: > > > > On Tue, Oct 29, 2019 at 6:29 PM Paul Walsh > wrote: > >> On Oct 29, 2019, at 11:17 AM, James Burton > > wrote: >> >> Hi Paul, >> >> I take the view that the articles on the CA

Re: [FORGED] Firefox removes UI for site identity

2019-10-29 Thread Paul Walsh via dev-security-policy
> On Oct 29, 2019, at 11:17 AM, James Burton wrote: > > Hi Paul, > > I take the view that the articles on the CA Security Council website are a > form of marketing gimmick with no value whatsoever. [PW] More useless feedback that only serves to insult someone trying their best to add value.

Re: [FORGED] Firefox removes UI for site identity

2019-10-29 Thread James Burton via dev-security-policy
Hi Paul, I take the view that the articles on the CA Security Council website are a form of marketing gimmick with no value whatsoever. Thank you Burton On Tue, Oct 29, 2019 at 5:55 PM Paul Walsh via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hi Nick, > > > On Oct

Re: [FORGED] Firefox removes UI for site identity

2019-10-29 Thread Paul Walsh via dev-security-policy
Hi Nick, > On Oct 29, 2019, at 7:07 AM, Nick Lamb wrote: > > On Mon, 28 Oct 2019 16:19:30 -0700 > Paul Walsh via dev-security-policy > wrote: >> If you believe the visual indicator has little or no value why did >> you add it? > > The EV indication dates back to the creation of Extended

Re: [FORGED] Firefox removes UI for site identity

2019-10-29 Thread Nick Lamb via dev-security-policy
On Mon, 28 Oct 2019 16:19:30 -0700 Paul Walsh via dev-security-policy wrote: > If you believe the visual indicator has little or no value why did > you add it? The EV indication dates back to the creation of Extended Validation, and so the CA/Browser forum, which is well over a decade ago now.