Groups
Groups
Sign in
Groups
Groups
dev-security-policy@mozilla.org
Conversations
About
Send feedback
Help
Group path
dev-security-policy@mozilla.org
1–30 of 395
Welcome to the dev-security-policy group in which we discuss issues concerning the Mozilla Root Program,
root store policy
development, governance matters, and other PKI topics directly relevant to the Program.
Mailing List:
dev-security-policy@mozilla.or
g
Web:
https://groups.google.com/a/mo
zilla.org/g/dev-security-polic
y
Participation Guidelines:
https://www.mozilla.org/about/
governance/policies/participat
ion/
Participants:
https://wiki.mozilla.org/CA/Po
licy_Participants
Unsubscribe by sending email to:
dev-security-policy+unsubscrib
e@mozilla.org
Previous list archives (2009-2021):
https://groups.google.com/g/mo
zilla.dev.security.policy
Mark all as read
Report group
0 selected
Wayne
, …
Mike Shaver
10
9:31 AM
CT Sanctions Watch
I agree this is a weedy and complex situation. Part of the reason for this existing is the lack of
unread,
CT Sanctions Watch
I agree this is a weedy and complex situation. Part of the reason for this existing is the lack of
9:31 AM
Wayne
2
9:15 AM
ccTLD Registrar Hijacks
I had a private request to look into the .ug hijack back in May. Here's the data for that, noting
unread,
ccTLD Registrar Hijacks
I had a private request to look into the .ug hijack back in May. Here's the data for that, noting
9:15 AM
Mike Shaver
,
Ben Wilson
2
Oct 5
Netlock inclusion in MRSP
Hi Mike, Thanks for raising this. We're considering the concerns you've identified as part of
unread,
Netlock inclusion in MRSP
Hi Mike, Thanks for raising this. We're considering the concerns you've identified as part of
Oct 5
Ben Wilson
,
Mike Shaver
3
Oct 5
Notice of Intent to Approve eMudhra's Root Inclusion Request
Hi Mike, Thanks for your suggestions. As noted in my response regarding GoDaddy, the CCADB Public
unread,
Notice of Intent to Approve eMudhra's Root Inclusion Request
Hi Mike, Thanks for your suggestions. As noted in my response regarding GoDaddy, the CCADB Public
Oct 5
Ben Wilson
, …
Mike Shaver
5
Oct 5
Notice of Intent to Approve GoDaddy's Root Inclusion Request
Hi Mike, Thanks for your suggestions. The CCADB Public discussion kickoff email already links to the
unread,
Notice of Intent to Approve GoDaddy's Root Inclusion Request
Hi Mike, Thanks for your suggestions. The CCADB Public discussion kickoff email already links to the
Oct 5
Ben Wilson
Sep 23
Detailed Control Reports Whitepaper Published — Feedback Welcome
Hello everyone, Following the discussion draft shared in July, version 1.0 of the Detailed Controls
unread,
Detailed Control Reports Whitepaper Published — Feedback Welcome
Hello everyone, Following the discussion draft shared in July, version 1.0 of the Detailed Controls
Sep 23
Rollin Yu
Sep 16
Reminder: 11 October 2026 DNS root KSK rollover — CA readiness for CAA/DCV
Hi all, A short operational reminder: on Sunday, 11 October 2026, KSK-2024 (key tag 38696) is
unread,
Reminder: 11 October 2026 DNS root KSK rollover — CA readiness for CAA/DCV
Hi all, A short operational reminder: on Sunday, 11 October 2026, KSK-2024 (key tag 38696) is
Sep 16
Suchan Seo
, …
Preston Locke
3
Sep 1
Can anyone access to old mozilla.dev.security.policy?
The Wayback Machine has a snapshot from earlier this month: https://web.archive.org/web/
unread,
Can anyone access to old mozilla.dev.security.policy?
The Wayback Machine has a snapshot from earlier this month: https://web.archive.org/web/
Sep 1
Adriano Santoni
, …
Ben Wilson
3
Aug 27
Suspicious comments being posted on Bugzilla incidents
Hi Adriano, Thank you for raising this concern. We are aware of the suspicious comments being posted
unread,
Suspicious comments being posted on Bugzilla incidents
Hi Adriano, Thank you for raising this concern. We are aware of the suspicious comments being posted
Aug 27
Wayne
,
Adriano Santoni
4
Aug 24
Cross-Validating Linters [zlint]
Okay finished up checking the other linters, attached an updated version of the zlint findings +
unread,
Cross-Validating Linters [zlint]
Okay finished up checking the other linters, attached an updated version of the zlint findings +
Aug 24
Ben Wilson
, …
Dimitris Zacharopoulos
7
Aug 18
Descriptive vs. normative language in CP/CPS documentation
On 8/17/2026 8:00 PM, 'Aaron Gable' via dev-secur...@mozilla.org wrote: I think
unread,
Descriptive vs. normative language in CP/CPS documentation
On 8/17/2026 8:00 PM, 'Aaron Gable' via dev-secur...@mozilla.org wrote: I think
Aug 18
Suchan Seo
,
Corey Bonnell
2
Aug 18
Can CA use HTTPS record (RFC 9460) to get IP address of domain?
For ACME http-01, using HTTPS records isn't allowed. TLS BR domain validation method 19 (ACME
unread,
Can CA use HTTPS record (RFC 9460) to get IP address of domain?
For ACME http-01, using HTTPS records isn't allowed. TLS BR domain validation method 19 (ACME
Aug 18
Wayne
, …
Luis Osses
10
Jul 28
MRSP Intermediate Violations (5.3), Mass Report of 26 Subordinate CAs
Hello Wayne, Thanks for dedicating the time for this research! Understanding that you already did a
unread,
MRSP Intermediate Violations (5.3), Mass Report of 26 Subordinate CAs
Hello Wayne, Thanks for dedicating the time for this research! Understanding that you already did a
Jul 28
Wayne
, …
Cynthia Revström
6
Jul 24
e164.arpa Usage
I'll admit that it was a bad example. It was just something I kinda tacked on at the end, it was
unread,
e164.arpa Usage
I'll admit that it was a bad example. It was just something I kinda tacked on at the end, it was
Jul 24
Ben Wilson
Jul 1
Discussion Draft: Detailed Controls Reports White Paper
Greetings, Following the publication of Mozilla Root Store Policy (MRSP) version 3.1 and the
unread,
Discussion Draft: Detailed Controls Reports White Paper
Greetings, Following the publication of Mozilla Root Store Policy (MRSP) version 3.1 and the
Jul 1
certifikati
Jun 29
NSS trust-store modification by official FINA Linux certificate client package
Subject: NSS trust-store modification by official FINA Linux certificate client package Dear Mozilla
unread,
NSS trust-store modification by official FINA Linux certificate client package
Subject: NSS trust-store modification by official FINA Linux certificate client package Dear Mozilla
Jun 29
Ben Wilson
Jun 29
MRSP 3.1: MRSP Publication and Guidance
All, Version 3.1 of the Mozilla Root Store Policy (MRSP) is now published. It has an effective date
unread,
MRSP 3.1: MRSP Publication and Guidance
All, Version 3.1 of the Mozilla Root Store Policy (MRSP) is now published. It has an effective date
Jun 29
Ben Wilson
Jun 14
MRSP 3.1: Planned Effective Date of 7/1/2026
All, We previously indicated an anticipated effective date for the Mozilla Root Store Policy (MRSP)
unread,
MRSP 3.1: Planned Effective Date of 7/1/2026
All, We previously indicated an anticipated effective date for the Mozilla Root Store Policy (MRSP)
Jun 14
Ben Wilson
Jun 5
Notice of Intent to Approve SECOM Trust Systems Co., Ltd. Root Inclusion Requests
Greetings, Public discussion regarding inclusion of the following SECOM Trust Systems Co., Ltd. root
unread,
Notice of Intent to Approve SECOM Trust Systems Co., Ltd. Root Inclusion Requests
Greetings, Public discussion regarding inclusion of the following SECOM Trust Systems Co., Ltd. root
Jun 5
Ben Wilson
Jun 5
Notice of Intent to Approve Telia's Root Inclusion Requests
Greetings, Public discussion regarding inclusion of the following Telia Company root CA certificates
unread,
Notice of Intent to Approve Telia's Root Inclusion Requests
Greetings, Public discussion regarding inclusion of the following Telia Company root CA certificates
Jun 5
Ben Wilson
2
Jun 1
MRSP 3.1: Results of CA Communication and Survey
Hello everyone, Thanks to the CA operators who participated in the recent Mozilla CA Operator
unread,
MRSP 3.1: Results of CA Communication and Survey
Hello everyone, Thanks to the CA operators who participated in the recent Mozilla CA Operator
Jun 1
Hanno Böck
, …
Q Misell
4
May 21
Microsoft MX servers use certificate chaining to obsolete DigiCert Global Root CA
Thanks Martijn for the reply. Considering your points, I agree and revise down my statement of this
unread,
Microsoft MX servers use certificate chaining to obsolete DigiCert Global Root CA
Thanks Martijn for the reply. Considering your points, I agree and revise down my statement of this
May 21
Ben Wilson
, …
Roman Fischer
18
May 15
MRSP 3.1: Issue #s 282 and 295: CP/CPS Documentation
Thanks for the clarifications, Ben. Looks good! -Roman From: 'Trevoli Ponds-White' via dev-
unread,
MRSP 3.1: Issue #s 282 and 295: CP/CPS Documentation
Thanks for the clarifications, Ben. Looks good! -Roman From: 'Trevoli Ponds-White' via dev-
May 15
Ben Wilson
May 14
Preliminary Report - Responses to Mozilla's May 2026 CA Survey
Hello everyone, Attached is a preliminary report summarizing the 14 responses received thus far to
unread,
Preliminary Report - Responses to Mozilla's May 2026 CA Survey
Hello everyone, Attached is a preliminary report summarizing the 14 responses received thus far to
May 14
Anupama M
,
Trevoli Ponds-White
4
May 14
MozillaIntermediateCertsCSVReport — blank line after -----BEGIN CERTIFICATE----- in 18 Amazon S-series rows
Thank you for the resolution Trevoli. On Thursday, May 14, 2026 at 2:28:15 AM UTC+5:30 Trevoli Ponds-
unread,
MozillaIntermediateCertsCSVReport — blank line after -----BEGIN CERTIFICATE----- in 18 Amazon S-series rows
Thank you for the resolution Trevoli. On Thursday, May 14, 2026 at 2:28:15 AM UTC+5:30 Trevoli Ponds-
May 14
Ben Wilson
, …
大野文彰(ONO Fumiaki)
9
May 14
MRSP 3.1: Issue #s 294, 296, 297, and 298: Audit-related Improvements
Hello Ben-san, Thank you for adding the requested language. This looks good from our side. Best
unread,
MRSP 3.1: Issue #s 294, 296, 297, and 298: Audit-related Improvements
Hello Ben-san, Thank you for adding the requested language. This looks good from our side. Best
May 14
Ben Wilson
,
Rob Stradling
3
May 6
Websites Trust Bit Removals for 2027
Thanks, Rob I'll update my table here - https://wiki.mozilla.org/CA/Root_CA_Lifecycles#
unread,
Websites Trust Bit Removals for 2027
Thanks, Rob I'll update my table here - https://wiki.mozilla.org/CA/Root_CA_Lifecycles#
May 6
Ben Wilson
Apr 27
MRSP 3.1: Draft CA Communication and Survey
All, I have prepared a draft CA communication and survey to send to CA operators that are either
unread,
MRSP 3.1: Draft CA Communication and Survey
All, I have prepared a draft CA communication and survey to send to CA operators that are either
Apr 27
Ben Wilson
Apr 27
MRSP 3.1: Issue #299: Mass Revocation Planning Audits
All, This email concerns the criteria for assessing the mass revocation planning efforts of CA
unread,
MRSP 3.1: Issue #299: Mass Revocation Planning Audits
All, This email concerns the criteria for assessing the mass revocation planning efforts of CA
Apr 27
Ben Wilson
,
Aaron Gable
3
Apr 26
MRSP 3.1: Issue #s 292 and 293: CA Operational Reporting and Policy Alignment
Hi Aaron, I tried to track these changes separately, but after merging them into my 3.1 branch I'
unread,
MRSP 3.1: Issue #s 292 and 293: CA Operational Reporting and Policy Alignment
Hi Aaron, I tried to track these changes separately, but after merging them into my 3.1 branch I'
Apr 26