Re: Request to Include certSIGN Root CA G2 certificate

2020-05-08 Thread Wayne Thayer via dev-security-policy
The ETSI audit attestation statement referenced by Ben [1] lists 6 non-conformities that were to be corrected within 3 months of the onsite audit that occurred on 2020-02-10 until 2020-02-14: Findings with regard to ETSI EN 319 401: -REQ-7.8-06–Documentation shall be improved Findings with

Mozilla's Expectations for OCSP Incident Reporting

2020-05-08 Thread Wayne Thayer via dev-security-policy
It was recently reported [1] that IdenTrust experienced a multi-day OCSP outage about two weeks ago. Other recent OCSP issues have resulted in incident reports [3][4], so I am concerned that IdenTrust didn't report this, and I created a bug [5] to ensure that we track the issue (assuming the

Re: DRAFT May 2020 CA Communication/Survey

2020-05-08 Thread Kathleen Wilson via dev-security-policy
On 5/7/20 11:33 AM, Kathleen Wilson wrote: > I have drafted a potential CA Communication and survey, and will greatly > appreciate your input on it. > > https://wiki.mozilla.org/CA/Communications#May_2020_CA_Communication > > Direct link to read-only copy of the draft survey: >