Re: Incident Reporting Guidance

2019-12-19 Thread Wayne Thayer via dev-security-policy
Having received no comments on this proposal, I went ahead and added it to the wiki [1]. - Wayne [1] https://wiki.mozilla.org/CA/Responding_To_An_Incident#Incident_Report On Wed, Dec 11, 2019 at 4:45 PM Wayne Thayer wrote: > While thinking about different ways to solve the problem of

Re: Incident Reporting Guidance

2019-12-11 Thread Wayne Thayer via dev-security-policy
While thinking about different ways to solve the problem of disclosing missed revocation deadlines, we devised a solution for searching and reporting on delayed revocations separately from other incidents. We've begun to add a new Bugzilla "whiteboard" label to delayed revocation incident bugs. We

Re: Incident Reporting Guidance

2019-11-21 Thread Ryan Sleevi via dev-security-policy
On Thu, Nov 21, 2019 at 10:54 AM Wayne Thayer via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > During the recent CA/Browser Forum meeting, I was asked to provide better > guidance on Mozilla's expectations for incident reporting. We're adding a > requirement for incident

Incident Reporting Guidance

2019-11-21 Thread Wayne Thayer via dev-security-policy
During the recent CA/Browser Forum meeting, I was asked to provide better guidance on Mozilla's expectations for incident reporting. We're adding a requirement for incident reporting to the new version of our policy [1], but in this message I'm focused on the guidance provided on our wiki [2]. The