Re: GTS - OCSP serving issue 2020-04-09

2020-04-18 Thread Ryan Sleevi via dev-security-policy
On Sat, Apr 18, 2020 at 6:39 PM Nick Lamb via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > What does "contractual jeopardy" mean here? The Baseline Requirements address this. See 9.16.3 (particularly item 5) and 9.6.1 (6). For better or worse, the situation is as Neil

Re: GTS - OCSP serving issue 2020-04-09

2020-04-18 Thread Nick Lamb via dev-security-policy
On Fri, 17 Apr 2020 18:34:00 +0100 Neil Dunbar via dev-security-policy wrote: > timestamp checking etc, etc]. Ryan's writeup calls out the revoked > situation under the heading of 'make sure it is something the client > will accept' - if the client understands OCSP responses at all, it > needs