Re: EKU is required in each Subordinate CA certificate

2020-08-29 Thread Ryan Sleevi via dev-security-policy
Glad to see you paying close attention to the Baseline Requirements changes! On Thu, Aug 27, 2020 at 1:34 PM Sándor dr. Szőke via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Yes, that date comes from the Mozilla Root Program, but this requirement > is new for the other R

Re: EKU is required in each Subordinate CA certificate

2020-08-27 Thread Sándor dr . Szőke via dev-security-policy
Yes, that date comes from the Mozilla Root Program, but this requirement is new for the other Root Programs and for the BR. The other thing is that without having an indicated effect date, the requirement can be interpreted in that way, that every valid Subordinate CA certificate shall comply t

EKU is required in each Subordinate CA certificate

2020-08-27 Thread Sándor dr . Szőke via dev-security-policy
You could find the following requirement in the latest Baseline Requirement: 7. CERTIFICATE, CRL, AND OCSP PROFILES 7.1 Certificate profile 7.1.2 Certificate Content and Extensions; Application of RFC 5280 7.1.2.2 Subordinate CA Certificate ... g. extkeyUsage (optional/required) For Cross Certific