AC Camerfirma's CP & CPS disclosure

2018-08-29 Thread Juan Angel Martin via dev-security-policy
1. We've been required by our auditors in their WebTrust Principles and Criteria for Certification Authorities v2.0 & Extended Validation SSL v1.6 Qualified Audits Reports of a series of changes that we must make in our CP & CPS W4CA https://bugzilla.mozilla.org/attachment.cgi?id=8995928 WEV

Equalization of criteria about CPS & CP with our auditors disclosure

2018-08-29 Thread juanangel.martingomez--- via dev-security-policy
1. We've been required by our auditors in their WebTrust Principles and Criteria for Certification Authorities v2.0 & Extended Validation SSL v1.6 Qualified Audits Reports of a series of changes that we must make in our CP & CPS W4CA https://bugzilla.mozilla.org/attachment.cgi?id=8995928 WEV

Re: Audit Reminder Email Summary

2018-08-29 Thread Ryan Sleevi via dev-security-policy
On Mon, Aug 27, 2018 at 2:25 AM reinhard.dietrich--- via dev-security-policy wrote: > Dear all > > This is a joint answer to Waynes' request. > > it was mentioned that the audit period was exceeded. We would like to > explain the situation and what was undertaken to avoid such situation again. >

Re: AC Camerfirma's CP & CPS disclosure

2018-08-29 Thread Wayne Thayer via dev-security-policy
Hello Juan, Was this message intended to be a response to the discussion of Camerfirma's qualified audits in https://bugzilla.mozilla.org/show_bug.cgi?id=1478933 ? I am awaiting a full response to comment #7 in which I requested a full remediation plan for the issues identified by these audits.