Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
TWCA Request to enable EV and turn on Code Signing trust bit
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 26 - 36 of 36 - Collapse all  -  Translate all to Translated (View all originals) < Older 
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Robin Lin  
View profile  
 More options Nov 12 2012, 9:08 pm
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Mon, 12 Nov 2012 18:08:07 -0800 (PST)
Local: Mon, Nov 12 2012 9:08 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
Jean-Marc Desperrier於 2012年11月13日星期二UTC+8上午6時28分36秒寫道:

I tried to search the ITU member states using following link:
http://www.itu.int/GlobalDirectory/search.html
There is no any member can proof that "Taiwan Registration and Certification Authority Inc." is the country RA of Taiwan.
The question is go back to the source, Taiwan is not a member body of ISO and ITU. There is no one can resolve this problem. As Erwann said, no one can first use then get it first, but why the country code "2.16.158" could be?

To avoid this issue, I will try to apply PEN from IANA and use our private CP OID to enable the EV function in Mozilla.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Lin  
View profile  
 More options Nov 15 2012, 8:39 pm
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Thu, 15 Nov 2012 17:39:07 -0800 (PST)
Local: Thurs, Nov 15 2012 8:39 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
About TWCA EV OID, we have send request to apply PEN to IANA, it will take 30 days. This is current solution to resolve the OID question here.

About the action TWCA must take:
1. Fix hostname to remove underscore character.
--->FIXED; the new OCSP responder is "evsslocsp.twca.com.tw"
2. Fix URI in certificatePolicies extension to be RFC 3986 compliant.
--->FIXED; CPS URI indicator is point to our repository.
3. Fix issues with OCSP certificate: email address in subjectAlternativeName, entropy, ocspNoCheck extension.
--->FIXED; we remove the email, add ocspNoCheck extension and use 24 bits radom number in the serial number.
4. Support OCSP GET
--->FIXED, support both POST and GET


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Lin  
View profile  
 More options Nov 15 2012, 8:39 pm
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Thu, 15 Nov 2012 17:39:07 -0800 (PST)
Local: Thurs, Nov 15 2012 8:39 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
About TWCA EV OID, we have send request to apply PEN to IANA, it will take 30 days. This is current solution to resolve the OID question here.

About the action TWCA must take:
1. Fix hostname to remove underscore character.
--->FIXED; the new OCSP responder is "evsslocsp.twca.com.tw"
2. Fix URI in certificatePolicies extension to be RFC 3986 compliant.
--->FIXED; CPS URI indicator is point to our repository.
3. Fix issues with OCSP certificate: email address in subjectAlternativeName, entropy, ocspNoCheck extension.
--->FIXED; we remove the email, add ocspNoCheck extension and use 24 bits radom number in the serial number.
4. Support OCSP GET
--->FIXED, support both POST and GET


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jean-Marc Desperrier  
View profile  
 More options Nov 19 2012, 7:44 am
Newsgroups: mozilla.dev.security.policy
From: Jean-Marc Desperrier <jmd...@gmail.com>
Date: Mon, 19 Nov 2012 13:44:45 +0100
Local: Mon, Nov 19 2012 7:44 am
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
Robin Lin a écrit :

> Jean-Marc Desperrier於 2012年11月13日星期二UTC+8上午6時28分36秒寫道:
>> On 12/11/2012 06:58, Robin Lin wrote:
>> The administration of the 2.16 arc of the ITU/ISO is described here
>> http://oid-info.com/get/2.16 , it says :
>> "The assignment of registration responsibilities within a country is a
>> national decision."

>> This document list the country RAs that the ITU recognizes and it does
>> officially recognize that one has been established for Taiwan :
>> http://www.oid-info.com/doc/country-OIDs.htm#agreements

> I tried to search the ITU member states using following link:
> http://www.itu.int/GlobalDirectory/search.html

We all agree Taiwan is not a member of ITU.

But the document I quoted does *not* require a country to be member to
have a recognized RA.

> There is no any member can proof that "Taiwan Registration and
> Certification Authority Inc." is the country RA of Taiwan.

The Project Leader of the ITU-T Study Group 7
(http://www.itu.int/en/ITU-T/about/groups/Pages/sg17.aspx in charge of
ITU security work coordination) *does* recognize this entity as the
country RA of Taiwan.

We could ask him on which document he relies to state that, and if there
can be an official document that indeed the ITU recognizes TRCA as the
entity currently in charge of the 2.16.258 arc.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Lin  
View profile  
 More options Nov 28 2012, 9:43 pm
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Wed, 28 Nov 2012 18:43:09 -0800 (PST)
Local: Wed, Nov 28 2012 9:43 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
Hi,

We had applied one PEN from IANA and will use it as our enterprise OID tree root.
The PEN of TWCA is "1.3.6.1.4.1.40869"

The IANA page is:
http://www.iana.org/assignments/enterprise-numbers

We are update our CP and CPS to use the new OID right now, and will post the updated CP/CPS URL here for your review.

Robin Lin


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Lin  
View profile  
 More options Nov 28 2012, 9:43 pm
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Wed, 28 Nov 2012 18:43:09 -0800 (PST)
Local: Wed, Nov 28 2012 9:43 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
Hi,

We had applied one PEN from IANA and will use it as our enterprise OID tree root.
The PEN of TWCA is "1.3.6.1.4.1.40869"

The IANA page is:
http://www.iana.org/assignments/enterprise-numbers

We are update our CP and CPS to use the new OID right now, and will post the updated CP/CPS URL here for your review.

Robin Lin


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Erwann Abalea  
View profile  
 More options Dec 2 2012, 9:42 am
Newsgroups: mozilla.dev.security.policy
From: Erwann Abalea <eaba...@gmail.com>
Date: Sun, 2 Dec 2012 06:42:35 -0800 (PST)
Local: Sun, Dec 2 2012 9:42 am
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
Bonjour,

Le jeudi 29 novembre 2012 03:43:09 UTC+1, Robin Lin a écrit :

> We had applied one PEN from IANA and will use it as our enterprise OID tree root.
> The PEN of TWCA is "1.3.6.1.4.1.40869"

Thanks.

> The IANA page is:

> http://www.iana.org/assignments/enterprise-numbers

> We are update our CP and CPS to use the new OID right now, and will post the updated CP/CPS URL here for your review.

Could you also please update the inclusion bug (#745671) to clearly indicate the desired EV policy OID under this arc?

Cordialement.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Lin  
View profile  
 More options Dec 6 2012, 12:51 am
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Wed, 5 Dec 2012 21:51:09 -0800 (PST)
Local: Thurs, Dec 6 2012 12:51 am
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
TWCA has been update EV OID, the CP/CPS are also available:
CP:
http://www.twca.com.tw/picture/file/12031626-Public%20Key%20Infrastru...

CPS:
http://www.twca.com.tw/picture/file/12031629-EV%20SSL%20CA%20Certific...

The new EV OID is:
1.3.6.1.4.1.40869.1.1.22.3

Also described as:
{ISO(1) identified-organization(3) dod(6) internet(1) private(4) enterprise(1) TWCA(40869) certificates(1) policies(1) EV(22) class3(3) }

This will no conflict with others since this is our own OID extend from our PEN.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Lin  
View profile  
 More options Dec 6 2012, 12:51 am
Newsgroups: mozilla.dev.security.policy
From: Robin Lin <robinwt....@gmail.com>
Date: Wed, 5 Dec 2012 21:51:09 -0800 (PST)
Local: Thurs, Dec 6 2012 12:51 am
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
TWCA has been update EV OID, the CP/CPS are also available:
CP:
http://www.twca.com.tw/picture/file/12031626-Public%20Key%20Infrastru...

CPS:
http://www.twca.com.tw/picture/file/12031629-EV%20SSL%20CA%20Certific...

The new EV OID is:
1.3.6.1.4.1.40869.1.1.22.3

Also described as:
{ISO(1) identified-organization(3) dod(6) internet(1) private(4) enterprise(1) TWCA(40869) certificates(1) policies(1) EV(22) class3(3) }

This will no conflict with others since this is our own OID extend from our PEN.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kathleen Wilson  
View profile  
 More options Dec 11 2012, 2:57 pm
Newsgroups: mozilla.dev.security.policy
From: Kathleen Wilson <kwil...@mozilla.com>
Date: Tue, 11 Dec 2012 11:57:08 -0800
Local: Tues, Dec 11 2012 2:57 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit

> On 11/15/12 5:39 PM, Robin Lin wrote:
>> About the action TWCA must take:
>> 1. Fix hostname to remove underscore character.
>> --->FIXED; the new OCSP responder is "evsslocsp.twca.com.tw"
>> 2. Fix URI in certificatePolicies extension to be RFC 3986 compliant.
>> --->FIXED; CPS URI indicator is point to our repository.
>> 3. Fix issues with OCSP certificate: email address in subjectAlternativeName, entropy, ocspNoCheck extension.
>> --->FIXED; we remove the email, add ocspNoCheck extension and use 24 bits radom number in the serial number.
>> 4. Support OCSP GET
>> --->FIXED, support both POST and GET

On 12/5/12 9:51 PM, Robin Lin wrote:

> TWCA has been update EV OID, the CP/CPS are also available:
> CP:
> http://www.twca.com.tw/picture/file/12031626-Public%20Key%20Infrastru...

> CPS:
> http://www.twca.com.tw/picture/file/12031629-EV%20SSL%20CA%20Certific...

> The new EV OID is:
> 1.3.6.1.4.1.40869.1.1.22.3

> Also described as:
> {ISO(1) identified-organization(3) dod(6) internet(1) private(4) enterprise(1) TWCA(40869) certificates(1) policies(1) EV(22) class3(3) }

> This will no conflict with others since this is our own OID extend from our PEN.

Thanks to all of you who have contributed to this discussion about
TWCA's request to turn on the Code Signing trust bit and enable EV for
the “TWCA Root Certification Authority” root certificate that was
included in NSS per bug #518503.

It is my opinion that all of the action items resulting from this
discussion have been completed,this discussion may be closed, and I
should recommend approval of this request in the bug.

As stated above, the EV Policy OID that will be used is:
1.3.6.1.4.1.40869.1.1.22.3

Thanks,
Kathleen


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kathleen Wilson  
View profile  
 More options Dec 12 2012, 3:14 pm
Newsgroups: mozilla.dev.security.policy
From: Kathleen Wilson <kwil...@mozilla.com>
Date: Wed, 12 Dec 2012 12:14:55 -0800
Local: Wed, Dec 12 2012 3:14 pm
Subject: Re: TWCA Request to enable EV and turn on Code Signing trust bit
On 12/11/12 11:57 AM, Kathleen Wilson wrote:

Thank you to those of you who reviewed and contributed to this
discussion about the request from TWCA to turn on the Code Signing trust
bit and enable EV for the “TWCA Root Certification Authority” root
certificate.

All of the action items that were identified during this discussion have
been resolved.

I am closing this discussion, and I will recommend approval in the bug.

https://bugzilla.mozilla.org/show_bug.cgi?id=745671

Any further follow-up on this request should be added directly to the bug.

Thanks,
Kathleen


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages < Older 
« Back to Discussions « Newer topic     Older topic »