Re: Remove old WoSign root certs from NSS

2017-09-01 Thread Gervase Markham via dev-security-policy
On 30/08/17 18:50, Kathleen Wilson wrote: > https://blog.mozilla.org/security/2017/08/30/removing-disabled-wosign-startcom-certificates-firefox-58/ > > I will look into getting this translated and published in China. Here are the links to the post in Chinese, kindly supplied by our colleagues:

Re: Remove old WoSign root certs from NSS

2017-08-30 Thread Percy via dev-security-policy
On Wednesday, August 30, 2017 at 11:15:04 AM UTC-7, Kathleen Wilson wrote: > Posted: > > https://blog.mozilla.org/security/2017/08/30/removing-disabled-wosign-startcom-certificates-firefox-58/ > > I will look into getting this translated and published in China. > > Thanks, > Kathleen Thank you

Re: Remove old WoSign root certs from NSS

2017-08-30 Thread Kathleen Wilson via dev-security-policy
Posted: https://blog.mozilla.org/security/2017/08/30/removing-disabled-wosign-startcom-certificates-firefox-58/ I will look into getting this translated and published in China. Thanks, Kathleen ___ dev-security-policy mailing list

Re: Remove old WoSign root certs from NSS

2017-08-30 Thread Percy via dev-security-policy
links to all of WoSign's announcement in case anyone want to verify. https://www.wosign.com/news/index.htm year 2017 https://www.wosign.com/news/index2016.htm year 2016 ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org

Re: Remove old WoSign root certs from NSS

2017-08-30 Thread Percy via dev-security-policy
In fact, can you tell us, when was the first time WoSign started to notify users about replacing certs? I've dig through all of WoSign's announcement and the first and in fact the ONLY announcement regarding replacing certs is dated July 10th, 2017 , titled Announcement regarding Google's

Re: Remove old WoSign root certs from NSS

2017-08-30 Thread Percy via dev-security-policy
It's true that the first post has a link to that second post. However, the related sentence is To learn more, please visit "Announcement regarding Google's decision on July 7th", with a hyperlink to the second post. And only the second post mentions anything about replacing certs. I hardly

RE: Remove old WoSign root certs from NSS

2017-08-29 Thread Richard Wang via dev-security-policy
-Original Message- From: dev-security-policy [mailto:dev-security-policy-bounces+richard=wosign@lists.mozilla.org] On Behalf Of Percy via dev-security-policy Sent: Wednesday, August 30, 2017 3:54 AM To: mozilla-dev-security-pol...@lists.mozilla.org Subject: Re: Remove old WoSign root certs

Re: Remove old WoSign root certs from NSS

2017-08-29 Thread Percy via dev-security-policy
On Sunday, August 27, 2017 at 10:59:48 PM UTC-7, Richard Wang wrote: > We released replacement notice in Chinese in our website: > https://www.wosign.com/news/announcement-about-Microsoft-Action-20170809.htm > https://www.wosign.com/news/announcement-about-Google-Action-20170710.htm >

RE: Remove old WoSign root certs from NSS

2017-08-28 Thread Richard Wang via dev-security-policy
@lists.mozilla.org] On Behalf Of Percy via dev-security-policy Sent: Monday, August 28, 2017 11:34 AM To: mozilla-dev-security-pol...@lists.mozilla.org Subject: Re: Remove old WoSign root certs from NSS On Friday, August 25, 2017 at 4:42:29 PM UTC-7, Kathleen Wilson wrote: > On Friday, Augus

Re: Remove old WoSign root certs from NSS

2017-08-27 Thread Percy via dev-security-policy
On Friday, August 25, 2017 at 4:42:29 PM UTC-7, Kathleen Wilson wrote: > On Friday, August 4, 2017 at 12:01:15 AM UTC-7, Percy wrote: > > I suggest that Mozilla can post an announcement now about the complete > > removal of WoSign/StartCom to alert website developers. I suspect that a > >

Re: Remove old WoSign root certs from NSS

2017-08-25 Thread Kathleen Wilson via dev-security-policy
On Friday, August 4, 2017 at 12:01:15 AM UTC-7, Percy wrote: > I suggest that Mozilla can post an announcement now about the complete > removal of WoSign/StartCom to alert website developers. I suspect that a > moderate amount of Chinese websites are still using WoSign certs chained to > the

Re: Remove old WoSign root certs from NSS

2017-08-04 Thread Percy via dev-security-policy
On Thursday, August 3, 2017 at 3:55:34 PM UTC-7, Kathleen Wilson wrote: > On Monday, July 10, 2017 at 12:47:31 PM UTC-7, Kathleen Wilson wrote: > > I also think we should remove the old WoSign root certs from NSS. > > > > Reference: > > https://wiki.mozilla.org/CA/Additional_Trust_Changes#WoSign

Re: Remove old WoSign root certs from NSS

2017-08-03 Thread Kathleen Wilson via dev-security-policy
On Monday, July 10, 2017 at 12:47:31 PM UTC-7, Kathleen Wilson wrote: > I also think we should remove the old WoSign root certs from NSS. > > Reference: > https://wiki.mozilla.org/CA/Additional_Trust_Changes#WoSign > ~~ > Mozilla currently recommends not trusting any certificates issued by this