Account Options

  1. Sign in
The old Google Groups will be going away soon.
Switch to the new Google Groups.
Google Groups Home
« Groups Home
Message from discussion CNNIC Root Inclusion
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Eddy Nigg  
View profile  
 More options Jan 28 2010, 6:43 am
Newsgroups: mozilla.dev.security.policy
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Thu, 28 Jan 2010 13:43:24 +0200
Local: Thurs, Jan 28 2010 6:43 am
Subject: Re: CNNIC Root Inclusion
On 01/28/2010 08:40 AM, Nelson Bolyard:

> Well, if that's the case, then the protests being lodged against CNNIC as
> an issuer of SSL server certs are all the more absurd.

Nelson, before commenting I suggest to read the concerns which were
raised at the comments posted at the bugs in order to understand what
they are. Those are starting from:

https://bugzilla.mozilla.org/show_bug.cgi?id=476766#c18

and

https://bugzilla.mozilla.org/show_bug.cgi?id=542689

> But my point is that any arguments that are based on the presence of malware
> are irrelevant and should not be considered in whether or not
> the CA acted properly as a CA.

This is not the issue, but it was provided by the concerned parties as
part of their "evidence" to confirm those concerns. The claims are
raised in the bug entries and at other places such as twitter and I
believe Mozilla and the community should at least listen to them and
consider if and how they are relevant regarding the root inclusion here.
Apparently there might be issues with the inclusion of this CA root
which we haven't considered here (because nobody raised any concern at
that time).

If the claims are correct, than this might be a serious cause for
concern and which might affect Mozilla policy requirements directly.
However I asked Kathleen to find the appropriate channels regarding
these claims because it's not something we've ever dealt with here.

--

Regards

Signer:  Eddy Nigg, StartCom Ltd.
XMPP:    start...@startcom.org
Blog:    http://blog.startcom.org/
Twitter: http://twitter.com/eddy_nigg


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.