I also oversaw that…

Anyhow… @Clint, what are the audit requirements for these clientAuth CAs?
In your program you mention WTBR as a requirement for "TLS CAs”, but there’s no 
distinction between clientAuth or serverAuth… while both are used to secure TLS 
handshakes.

> On 17 May 2024, at 11:22, Dimitris Zacharopoulos (HARICA) 
> <[email protected]> wrote:
> 
> 
> 
> On 16/5/2024 10:29 μ.μ., Clint Wilson wrote:
>>> AFAIK Apple and Mozilla also don't have a specific "trust bit" for Client 
>>> Authentication. Only Microsoft does.
>> FWIW, Apple does indeed have a specific trust bit for id-kp-clientAuth EKU 
>> and allows for (and ships) dedicated clientAuth Root CAs in the Apple Root 
>> Program (as outlined in 2.1.3 of the ARP Policy).
>> 
> 
> Thanks for the correction Clint. I had the impression that you shipped only 
> Apple Roots for clientAuth. My bad.
> 
> Dimitris.
> 
> 
> 


WISeKey SA
Pedro Fuentes
CSO - Trust Services Manager
Office: + 41 (0) 22 594 30 00
Mobile: + 41 (0) 791 274 790
Address: Avenue Louis-Casaï 58 | 1216 Cointrin | Switzerland
Stay connected with WISeKey <http://www.wisekey.com/>

THIS IS A TRUSTED MAIL: This message is digitally signed with a WISeKey 
identity. If you get a mail from WISeKey please check the signature to avoid 
security risks

CONFIDENTIALITY: This email and any files transmitted with it can be 
confidential and it’s intended solely for the use of the individual or entity 
to which they are addressed. If you are not the named addressee you should not 
disseminate, distribute or copy this e-mail. If you have received this email in 
error please notify the sender

DISCLAIMER: WISeKey does not warrant the accuracy or completeness of this 
message and does not accept any liability for any errors or omissions herein as 
this message has been transmitted over a public network. Internet 
communications cannot be guaranteed to be secure or error-free as information 
may be intercepted, corrupted, or contain viruses. Attachments to this e-mail 
are checked for viruses; however, we do not accept any liability for any damage 
sustained by viruses and therefore you are kindly requested to check for 
viruses upon receipt.

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Servercert-wg mailing list
[email protected]
https://lists.cabforum.org/mailman/listinfo/servercert-wg

Reply via email to