Re: Public CA:certs with unregistered FQDN mis-issuance

2019-05-31 Thread lcchen.cissp--- via dev-security-policy
lcche...@gmail.com於 2019年3月1日星期五 UTC+8上午12時48分27秒寫道: > 7. List of steps your CA is taking to resolve the situation and ensure such > issuance will not be repeated in the future, accompanied with a timeline of > when your CA expects to accomplish these things. > > Ans: > To avoid making the

Re: Public CA:certs with unregistered FQDN mis-issuance

2019-03-30 Thread lcchen.cissp--- via dev-security-policy
lcche...@gmail.com於 2019年3月1日星期五 UTC+8上午12時48分27秒寫道: > > 7. List of steps your CA is taking to resolve the situation and ensure such > issuance will not be repeated in the future, accompanied with a timeline of > when your CA expects to accomplish these things. > > Ans: > To avoid making the

Public CA:certs with unregistered FQDN mis-issuance

2019-02-28 Thread lcchen.cissp--- via dev-security-policy
1. How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a Bugzilla bug, or internal self-audit), and the time and date. Ans: One of our staffs in PKI group was taking samples of

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-07-14 Thread lcchen.cissp--- via dev-security-policy
Wayne Thayer於 2018年7月14日星期六 UTC+8上午1時16分58秒寫道: > > In effect, this is saying that CAs should be permitted to break > well-defined rules when they find them inconvenient. This is the second > example in which Chunghwa Telecom has argued that it's okay to do this > (along with the Taiwan

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-07-13 Thread lcchen.cissp--- via dev-security-policy
> [2] https://bug1341604.bmoattachments.org/attachment.cgi?id=8974418 > [3] https://bug1341604.bmoattachments.org/attachment.cgi?id=8974418#c66 > > > On Tue, Jul 10, 2018 at 7:58 AM lcchen.cissp--- via dev-security-policy < > dev-security-policy@lists.mozilla.org> wr

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-07-10 Thread lcchen.cissp--- via dev-security-policy
lcchen...@gmail.com於 2018年6月5日星期二 UTC+8下午5時22分40秒寫道: > Wayne Thayer於 2018年5月19日星期六 UTC+8上午8時13分15秒寫道: > > This request is for inclusion of the Chunghwa Telecom eCA as documented in > > the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1341604 > > > > > > ==Bad== > > * A large

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-07-08 Thread lcchen.cissp--- via dev-security-policy
Dear Wayne, The previous email has some typos, corrected as follows. 1. When I was back to my office after the travlelling from England and disussed with my colleauges, I mailed the situation and the plan to Wayne and Kathleen on June 15. > When I was back to my office after the

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-07-07 Thread lcchen.cissp--- via dev-security-policy
Dear Wayne, Our two customers requested to use original CSR to issue two shorter validity SSL certificates. By the re-issuance function of a program, to insert original applications data, our SSL RA Officers checked the addresses but they forgot to add L in Subject DN. So there are two SSL

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-06-07 Thread lcchen.cissp--- via dev-security-policy
lcchen...@gmail.com於 2018年6月5日星期二 UTC+8下午6時25分00秒寫道: > lcchen...@gmail.com於 2018年6月5日星期二 UTC+8下午5時22分40秒寫道: > > > > > 1. We plan to modify the format of this type of certificate. The new > > certificate format will contain an EKU that excludes anyPolicy, > > emailProtection and serverAuth;

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-06-05 Thread lcchen.cissp--- via dev-security-policy
lcchen...@gmail.com於 2018年6月5日星期二 UTC+8下午5時22分40秒寫道: > > 1. We plan to modify the format of this type of certificate. The new > certificate format will contain an EKU that excludes anyPolicy, > emailProtection and serverAuth; besides, there will be no SubjectAltName > anymore. In other words,

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-06-05 Thread lcchen.cissp--- via dev-security-policy
Wayne Thayer於 2018年5月19日星期六 UTC+8上午8時13分15秒寫道: > This request is for inclusion of the Chunghwa Telecom eCA as documented in > the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1341604 > ==Bad== > * A large number of certificates have been misissued from the “Public >

Re: Chunghwa Telecom eCA Root Inclusion Request

2018-06-02 Thread lcchen.cissp--- via dev-security-policy
Wayne Thayer於 2018年5月19日星期六 UTC+8上午8時13分15秒寫道: > This request is for inclusion of the Chunghwa Telecom eCA as documented in > the following bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1341604 > I’ve reviewed the CPS, BR Self Assessment, and related information for the > Chunghwa Telecom