Re: Incident Report : GlobalSign certificates with ROCA Fingerprint

2017-11-07 Thread Gervase Markham via dev-security-policy
On 03/11/17 18:16, douglas.beat...@gmail.com wrote: > Here is the final incident report Thanks, Doug :-) Gerv ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy

Re: Incident Report : GlobalSign certificates with ROCA Fingerprint

2017-11-03 Thread douglas.beattie--- via dev-security-policy
Here is the final incident report 1) How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, via a discussion in mozilla.dev.security.policy, or via a Bugzilla bug), and the time and date. We became aware of the issue on October 16

Incident Report : GlobalSign certificates with ROCA Fingerprint

2017-10-31 Thread Kathleen Wilson via dev-security-policy
- Sent: Monday, October 30, 2017 1:36 PM To: mozilla-dev-security-policy Subject: Incident Report : GlobalSign certificates with ROCA Fingerprint I wanted to send out a status of where we are on the ROCA vulnerable certificates issued by GlobalSign. A full report will be coming later this week once

Incident Report : GlobalSign certificates with ROCA Fingerprint

2017-10-30 Thread Doug Beattie via dev-security-policy
I wanted to send out a status of where we are on the ROCA vulnerable certificates issued by GlobalSign. A full report will be coming later this week once we've completed the revocations, but here is a summary of the scope and status as it stands right now. Here's the Timeline: 10/16: Became a