Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Kathleen Wilson
I have sent the email to the following CAs. Root Owner | # Certs still to add to Salesforce Actalis 2 Asseco Data Systems S.A. (previously Unizeto Certum)1 Atos3 Autoridad de Certificacion Firmaprofesional 6 Camerfirma 19 certSIGN6 China Internet Network

Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Kathleen Wilson
On Thursday, October 27, 2016 at 4:14:35 AM UTC-7, Rob Stradling wrote: > So, to ensure that no CA can claim that they didn't know, I'd like to > see the "must keep disclosing intermediates to Salesforce on an ongoing > basis" requirement explicitly stated: > 1. in the next version of the

Re: Draft Email - Non-Disclosed SubCAs

2016-10-27 Thread Rob Stradling
On 27/10/16 09:31, Gervase Markham wrote: > On 26/10/16 22:02, Kathleen Wilson wrote: >> Please see >> https://wiki.mozilla.org/CA:SalesforceCommunity#CA_Community_in_Salesforce >> and let me know if you still think we need to add a sentence to the >> wiki page stating that CAs are expected to

Re: Draft Email - Non-Disclosed SubCAs

2016-10-26 Thread Kathleen Wilson
To be clear, this particular email will just be going to the CAs listed here: https://crt.sh/mozilla-disclosures#undisclosedsummary The intention of the email is to remind those CAs that they have an overdue action item, that needs to be completed. It is not the intention of this email to

Re: Draft Email - Non-Disclosed SubCAs

2016-10-22 Thread Jakob Bohm
On 21/10/2016 00:24, Gervase Markham wrote: On 20/10/16 15:05, Kathleen Wilson wrote: You are receiving this email because our records indicate that there are non-technically-constrained intermediate certificates that chain up to your root certificates that are included in Mozilla’s program

Re: Draft Email - Non-Disclosed SubCAs

2016-10-21 Thread Peter Bowen
onduct a search. > > From: Peter Bowen > Sent: ‎10/‎21/‎2016 10:08 AM > To: Kathleen Wilson > Cc: mozilla-dev-security-pol...@lists.mozilla.org > Subject: Re: Draft Email - Non-Disclosed SubCAs > > On Thu, Oct 20, 2016 at 1:09 PM, Kathleen Wilso

Re: Draft Email - Non-Disclosed SubCAs

2016-10-21 Thread Gervase Markham
On 20/10/16 13:09, Kathleen Wilson wrote: > Next week I expect to have a better capability for sending > notification emails to CAs. The first email I would like to try this > new tool on is regarding the CAs who have not disclosed all of their > non-technically-constrained intermediate

RE: Draft Email - Non-Disclosed SubCAs

2016-10-21 Thread Ben Wilson
:08 AM To: Kathleen Wilson<mailto:kwil...@mozilla.com> Cc: mozilla-dev-security-pol...@lists.mozilla.org<mailto:mozilla-dev-security-pol...@lists.mozilla.org> Subject: Re: Draft Email - Non-Disclosed SubCAs On Thu, Oct 20, 2016 at 1:09 PM, Kathleen Wilson <kwil...@mozilla.com> wr

Re: Draft Email - Non-Disclosed SubCAs

2016-10-20 Thread Gervase Markham
On 20/10/16 15:05, Kathleen Wilson wrote: > You are receiving this email because our records indicate that there > are non-technically-constrained intermediate certificates that chain > up to your root certificates that are included in Mozilla’s program > that have not been entered into the CA

Re: Draft Email - Non-Disclosed SubCAs

2016-10-20 Thread Kathleen Wilson
On Thursday, October 20, 2016 at 2:24:19 PM UTC-7, Florian Weimer wrote: > > Does this requirement apply transitively sub-CAs of sub-CAs? > > It may make sense to stress explicitly that the “technically > constrained” refers to properties visible in the certificates > themselves, not technical

Re: Draft Email - Non-Disclosed SubCAs

2016-10-20 Thread Florian Weimer
* Kathleen Wilson: > The following was stated in Mozilla’s March 2016 CA Communication > (https://wiki.mozilla.org/CA:Communications#March_2016): > Beginning with Version 2.1 of Mozilla's CA Certificate Policy, for any > certificate which directly or transitively chains to the root > certificates