Re: SHA-1 serverAuth cert issued by Trustis in November 2016

2017-02-24 Thread blake.morgan--- via dev-security-policy
On Monday, February 20, 2017 at 11:50:59 AM UTC, Gervase Markham wrote: > On 16/02/17 18:26, blake.mor...@trustis.com wrote: > > Trustis has now revoked the SHA-1 Certificate for hmrcset.trustis.com > > and replaced it with a SHA-256 Certificate. This status is reflected > > in the latest CRL. >

Re: SHA-1 serverAuth cert issued by Trustis in November 2016

2017-02-16 Thread blake.morgan--- via dev-security-policy
On Wednesday, February 15, 2017 at 10:02:50 PM UTC, Rob Stradling wrote: > This currently unrevoked cert has a SHA-1/RSA signature, the serverAuth > EKU and CN=hmrcset.trustis.com: > https://crt.sh/?id=50773741=cablint > > It lacks the SAN extension, but that doesn't excuse it from the ban on >

Re: SHA-1 serverAuth cert issued by Trustis in November 2016

2017-04-21 Thread blake.morgan--- via dev-security-policy
On Thursday, March 16, 2017 at 11:00:51 AM UTC, Gervase Markham wrote: > Hi Blake, > > On 02/03/17 16:26, blake morgan wrote: > > We have engaged with our external auditors in relation to this and the > > previous certificate that was reported. Once that activity has concluded we > > will be

Re: SHA-1 serverAuth cert issued by Trustis in November 2016

2017-03-02 Thread blake.morgan--- via dev-security-policy
On Friday, February 24, 2017 at 11:25:22 PM UTC, Gervase Markham wrote: > On 24/02/17 08:25, Andrew Ayer wrote: > > Below is an unrevoked SHA-1 serverAuth certificate for > > getset.trustis.com issued from this CA with a Not Before date of > > 2016-11-07. > > Blake: you wrote: "As part of the