Re: Expired Root CA in certdata.txt

2019-07-17 Thread Vincent Lours via dev-security-policy
Thanks guys for all those clarifications. Always good to learn new stuffs ^^ So I don't have to be worried about some Trust anchors expiring :) Have a good day. This topic can be closed. ___ dev-security-policy mailing list dev-security-policy@lists.

Re: Expired Root CA in certdata.txt

2019-07-15 Thread Jakob Bohm via dev-security-policy
As Mozilla has stopped caring about code signatures, e-mails are much more relevant for checking old certificates as of a known date: Most e-mail systems provide the reader with a locally verified record of when exactly the mail contents reached a trusted mail server and/or a POP3 client. Thus v

Re: Expired Root CA in certdata.txt

2019-07-14 Thread Ryan Sleevi via dev-security-policy
On Sun, Jul 14, 2019 at 8:32 PM Vincent Lours via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Monday, 15 July 2019 04:41:12 UTC+10, Ryan Sleevi wrote: > > Thanks for mentioning this here. > > > > Could you explain why you see it as an issue? RFC 5280 defines a trust >

Re: Expired Root CA in certdata.txt

2019-07-14 Thread Samuel Pinder via dev-security-policy
The way I understand it is, generally speaking, Root CAs may be kept in a root store for as long as the root key material is not compromised in any way. In practice Root CA certificates are removed at the operator's request when they believe it is no longer needed, or the root store operator believ

Re: Expired Root CA in certdata.txt

2019-07-14 Thread Vincent Lours via dev-security-policy
On Monday, 15 July 2019 04:41:12 UTC+10, Ryan Sleevi wrote: > Thanks for mentioning this here. > > Could you explain why you see it as an issue? RFC 5280 defines a trust > anchor as a subject and a public key. Everything else is optional, and the > delivery of a trust anchor as a certificate does

Re: Expired Root CA in certdata.txt

2019-07-14 Thread Ryan Sleevi via dev-security-policy
Thanks for mentioning this here. Could you explain why you see it as an issue? RFC 5280 defines a trust anchor as a subject and a public key. Everything else is optional, and the delivery of a trust anchor as a certificate does not necessarily imply the constraints of that certificate, including e

Expired Root CA in certdata.txt

2019-07-14 Thread Vincent Lours via dev-security-policy
Hi there, Following my "question" in the Mozilla Support Forum (https://support.mozilla.org/en-US/questions/1264544), I would like to notice you that there are 2 certificates expired in your Root CA file certdata.txt. The following certificates expired days ago: | Expiration date | Certificate