Re: Terms and Conditions that use technical measures to make it difficult to change CAs

2020-04-14 Thread Ryan Sleevi via dev-security-policy
On Tue, Apr 14, 2020 at 8:13 PM Robin Alden wrote: > I am ambivalent to the idea of having a list of business practices, > presumably over and above those required in law, that CAs must publish to > the community. I know it was more an aside, but I’m not sure I follow what you mean by “over an

RE: Terms and Conditions that use technical measures to make it difficult to change CAs

2020-04-14 Thread Robin Alden via dev-security-policy
> .. There’s plenty of precedent in having Root Policy or the > Baseline Requirements require a CP/CPS explicitly state something; > examples such as the CAA domain name, the problem reporting mechanism > and contact address, and compliance to the latest version of the BRs. > > If we apply that

GTS - OCSP serving issue 2020-04-09

2020-04-14 Thread Andy Warner via dev-security-policy
m.d.s.p community, Google Trust Services just filed https://bugzilla.mozilla.org/show_bug.cgi?id=1630040 which contains the same information as the report that follows. >From 2020-04-08 16:25 UTC to 2020-04-09 05:40 UTC, Google Trust Services' EJBCA based CAs (GIAG4, GIAG4ECC, GTSY1-4) served

Re: Welcome Ben Wilson to Mozilla!

2020-04-14 Thread Jeff Ward via dev-security-policy
On Monday, April 13, 2020 at 12:07:40 PM UTC-5, Kathleen Wilson wrote: > All, > > I am pleased to announce that Ben Wilson has joined Mozilla as a CA > Program Manager! > > Ben has worked in PKI security, compliance, and policy since 1998. > Previously, he worked at DigiCert in various roles,