--
You received this message because you are subscribed to the Google Groups "Certificate Transparency Policy" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ct-policy+...@chromium.org.
To post to this group, send email to ct-p...@chromium.org.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/ct-policy/CABP-pSQgKzGxBJL%3D%3DOOEEZEJRb3jM1868TugX8qWPSJTQ%2B3VMg%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "Certificate Transparency Policy" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ct-policy+...@chromium.org.
To post to this group, send email to ct-p...@chromium.org.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/ct-policy/deb54936-d216-4645-b4f0-a5522644b54d%40chromium.org.
As of 21 September 2018, 17:05 (UTC+8), the tree size of the GDCA CT Log 1 has exceeded 13000, and has been operating normally. No other problem report was received, we are wondering if you have any other comments or suggestions?
Thanks.
Xiu Lei
GDCA
--
You received this message because you are subscribed to the Google Groups "Certificate Transparency Policy" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ct-policy+...@chromium.org.
To post to this group, send email to ct-p...@chromium.org.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/ct-policy/dcbabcd5-131f-400f-a932-8ae37f87f981%40chromium.org.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/ct-policy/CAEyg3AE6r5CL1%2B3O2_kTYAANMJmP%2BAjLJj6%2BHb_KorraS-0%2Bpw%40mail.gmail.com.
Hi Xiu Lei,
Due GDCA Log 1 violating its MMD for certificates logged during a reconfiguration of the CT Log server, Chrome will not be including this Log as a Qualified Log. Given that the failure occurred before it was added to the Chromium code base, this course of action presents the least amount of risk to Chrome clients. GDCA is welcome to apply for qualification with a new CT Log with new key material by filing a new application as described in the Chrome Log Policy and we strongly encourage pursuing the use of an actively maintained CT Log code base.
While GDCA Log 2 has not violated Chrome CT Log Policy, we are still concerned that it was a routine operational procedure that caused GDCA Log 1 to violate its MMD and it’s not clear whether the proposed operational control or those already in place would have protected GDCA Log 2 from a similar failure.
Failure to incorporate certificates after issuing a SCT is one of the more serious failure modes for a CT Log. Before qualifying this new CT Log to be relied upon by CAs, Chrome, and other CT-enforcing user agents, we would like to know in greater detail what steps are being taken to mitigate the risk of this or similar failure modes once qualified.
Thanks.
Xiu Lei