Re: TLS certificates for ECIES keys

2020-11-02 Thread Devon O'Brien via dev-security-policy
Hi Jacob, I’m chiming in in my official capacity as a member of Chrome’s root program and its Certificate Transparency lead. Over the past several years, the narrowing of scope for both the web PKI and CT has been highly intentional. Great efforts have been made to ensure that use cases

Re: TLS certificates for ECIES keys

2020-10-30 Thread Devon O'Brien via dev-security-policy
Hi Bailey, You mention that all certificates involved in this design are checked for expiration, revocation, and Certificate Transparency using all of the same logic that verifies TLS certificates on Apple platforms, but notably, the custom evaluation policy for the Apple-issued certificate

DarkMatter CAs in Google Chrome and Android

2019-07-23 Thread Devon O'Brien via dev-security-policy
(Writing on behalf of Google Chrome and Android) On behalf of Google Chrome and Android, we would like to thank the participants that have contributed to the discussion on the broader M.D.S.P thread on this topic. We will be taking similar steps to those proposed by Wayne and approved by

Re: Symantec Update on SubCA Proposal

2017-08-09 Thread Devon O'Brien via dev-security-policy
Hello m.d.s.p., I'd just like to give the community a heads up that Chrome’s plan remains to put up a blog post echoing our recent announcement on blink-dev [1], but in the meantime, we are reviewing the facts related to Symantec’s sale of their PKI business to DigiCert [2]. Recently, it has