Groups
Groups
Sign in
Groups
Groups
dev-security-policy@mozilla.org
Conversations
About
Send feedback
Help
dev-security-policy@mozilla.org
1–30 of 368
Welcome to the dev-security-policy group in which we discuss issues concerning the Mozilla Root Program,
root store policy
development, governance matters, and other PKI topics directly relevant to the Program.
Mailing List:
dev-security-policy@mozilla.or
g
Web:
https://groups.google.com/a/mo
zilla.org/g/dev-security-polic
y
Participation Guidelines:
https://www.mozilla.org/about/
governance/policies/participat
ion/
Participants:
https://wiki.mozilla.org/CA/Po
licy_Participants
Unsubscribe by sending email to:
dev-security-policy+unsubscrib
e@mozilla.org
Previous list archives (2009-2021):
https://groups.google.com/g/mo
zilla.dev.security.policy
Mark all as read
Report group
0 selected
Ben Wilson
, …
Aaron Gable
3
Apr 24
MRSP 3.1: Issue #s 294, 296, 297, and 298: Audit-related Improvements
For #294 (Key Generation Recency): No comment, looks good. For #298 (Continuous Audit Coverage):
unread,
MRSP 3.1: Issue #s 294, 296, 297, and 298: Audit-related Improvements
For #294 (Key Generation Recency): No comment, looks good. For #298 (Continuous Audit Coverage):
Apr 24
Ben Wilson
,
Aaron Gable
2
Apr 24
MRSP 3.1: Issue #s 292 and 293: CA Operational Reporting and Policy Alignment
Both of these changes look good to me. It's a bit difficult to isolate them in the whole-file
unread,
MRSP 3.1: Issue #s 292 and 293: CA Operational Reporting and Policy Alignment
Both of these changes look good to me. It's a bit difficult to isolate them in the whole-file
Apr 24
Ben Wilson
, …
Aaron Gable
3
Apr 24
MRSP 3.1: Issue #s 282 and 295: CP/CPS Documentation
I concur, the changes related to CPS content seem good and don't seem onerous. I have one minor
unread,
MRSP 3.1: Issue #s 282 and 295: CP/CPS Documentation
I concur, the changes related to CPS content seem good and don't seem onerous. I have one minor
Apr 24
Ben Wilson
Apr 23
MRSP 3.1: Issue #291: Change in Ownership or Control
All, This is the last thread introducing this batch of changes to the Mozilla Root Store Policy (MRSP
unread,
MRSP 3.1: Issue #291: Change in Ownership or Control
All, This is the last thread introducing this batch of changes to the Mozilla Root Store Policy (MRSP
Apr 23
Ben Wilson
Apr 21
MRSP 3.1: Candidate Issues
All, I have reviewed the open issues in the mozilla/pkipolicy repository and identified a set of
unread,
MRSP 3.1: Candidate Issues
All, I have reviewed the open issues in the mozilla/pkipolicy repository and identified a set of
Apr 21
Ben Wilson
Apr 16
Approval of Cybertrust Japan SecureSign Root CA16
All, Public discussion of the Cybertrust Japan SecureSign Root CA16 (email trust bit)[1] occurred in
unread,
Approval of Cybertrust Japan SecureSign Root CA16
All, Public discussion of the Cybertrust Japan SecureSign Root CA16 (email trust bit)[1] occurred in
Apr 16
Awel Dia
,
Arabella Barks
2
Apr 10
Questions Regarding the Use of the id-ad-caIssuers Extension under the BR!
Hi Awel, BR do not impose any restrictions that the id-ad-caIssuers extension must point only to a
unread,
Questions Regarding the Use of the id-ad-caIssuers Extension under the BR!
Hi Awel, BR do not impose any restrictions that the id-ad-caIssuers extension must point only to a
Apr 10
Wayne
, …
Fabien Hochstrasser
5
Apr 8
EJBCA - Open MPIC Issues and Impacted CAs
Hi, I am posting this message on behalf of Google Trust Services. We stopped using EJBCA in 2023. As
unread,
EJBCA - Open MPIC Issues and Impacted CAs
Hi, I am posting this message on behalf of Google Trust Services. We stopped using EJBCA in 2023. As
Apr 8
Ben Wilson
Apr 8
Upcoming April 2026 NSS Root Store Changes (Bug 2017317)
Greetings, Mozilla will be making several root store changes in its April 2026 NSS release, as
unread,
Upcoming April 2026 NSS Root Store Changes (Bug 2017317)
Greetings, Mozilla will be making several root store changes in its April 2026 NSS release, as
Apr 8
Aaron Gable
, …
Ryan Hurst
21
Apr 3
Recent incidents regarding recording Baseline Requirements version
I am sorry, I meant for this to go to the ballot discussion and not here. Please direct any comments
unread,
Recent incidents regarding recording Baseline Requirements version
I am sorry, I meant for this to go to the ballot discussion and not here. Please direct any comments
Apr 3
Rebecca Kelley
3
Mar 25
Notification of acquisition of VikingCloud’s Digital Certificate Business
On March 6, 2026, SSL.com successfully completed the acquisition of VikingCloud, with the transfer of
unread,
Notification of acquisition of VikingCloud’s Digital Certificate Business
On March 6, 2026, SSL.com successfully completed the acquisition of VikingCloud, with the transfer of
Mar 25
Michael Stone
, …
Peter Bowen
6
Mar 24
Clarification on CAA NXDOMAIN handling: RFC 8659 vs. BR / Bug 1695786
Hi Peter, According to this decision flow, I think it's okay for a CA to issue certificates: ```
unread,
Clarification on CAA NXDOMAIN handling: RFC 8659 vs. BR / Bug 1695786
Hi Peter, According to this decision flow, I think it's okay for a CA to issue certificates: ```
Mar 24
Awel Dia
,
Henry Birge-Lee
3
Mar 18
CAA Checking: CNAME Target Returns SERVFAIL
Hi.Henry! Thank you very much for sharing. First, I would like to share the dig commands I used and
unread,
CAA Checking: CNAME Target Returns SERVFAIL
Hi.Henry! Thank you very much for sharing. First, I would like to share the dig commands I used and
Mar 18
Wayne
, …
Bas Westerbaan
4
Mar 17
Irregular RSA Exponents
Agreed. (Although I don't think that it should weigh heavily if at all, I do want to note that
unread,
Irregular RSA Exponents
Agreed. (Although I don't think that it should weigh heavily if at all, I do want to note that
Mar 17
Yuwei HAN (hanyuwei70)
, …
Aaron Gable
7
Mar 16
Revocation method is missing by subCA
Notice that the OCSP response contains a nextUpdate field; OCSP responses may be cached and reused
unread,
Revocation method is missing by subCA
Notice that the OCSP response contains a nextUpdate field; OCSP responses may be cached and reused
Mar 16
Ben Wilson
2
Mar 5
Public Discussion: Approval of JPRS as an Externally-Operated Subordinate CA under SECOM Root
Greetings, The three-week public discussion period regarding SECOM Trust Systems CO., LTD.'s
unread,
Public Discussion: Approval of JPRS as an Externally-Operated Subordinate CA under SECOM Root
Greetings, The three-week public discussion period regarding SECOM Trust Systems CO., LTD.'s
Mar 5
Arabella Barks
,
Rob Stradling
2
Feb 24
https://opensource.apple.com/source/security_certificates/ is 404
Hi Arabella. Here's the content that used to be at that URL: https://web.archive.org/web/
unread,
https://opensource.apple.com/source/security_certificates/ is 404
Hi Arabella. Here's the content that used to be at that URL: https://web.archive.org/web/
Feb 24
大野 文彰
,
Aaron Gable
3
Feb 24
Understanding accounturi handling across manual and ACME issuance (RFC 8657 Section 5.3)
Hi Aaron-san, Thank you for the clear and helpful response. I understand your point that the main
unread,
Understanding accounturi handling across manual and ACME issuance (RFC 8657 Section 5.3)
Hi Aaron-san, Thank you for the clear and helpful response. I understand your point that the main
Feb 24
Peter Mate Erdosi
,
Ben Wilson
2
Feb 12
Question about a Microsoft Root Program reuqirement
Hi Peter, My interpretation, which I limit to the text being discussed here, is that the policy OID
unread,
Question about a Microsoft Root Program reuqirement
Hi Peter, My interpretation, which I limit to the text being discussed here, is that the policy OID
Feb 12
Ben Wilson
, …
Joe DeBlasio
4
Feb 5
Updated Mozilla CT Log Policy
Yes, Mozilla did ask for, and get, Google's permission to use Chrome's lists as the basis for
unread,
Updated Mozilla CT Log Policy
Yes, Mozilla did ask for, and get, Google's permission to use Chrome's lists as the basis for
Feb 5
Ben Wilson
Feb 2
Removal of 'non-disclosable intermediate certificates' language from Mozilla CA Wiki
All, We have removed the section of this Mozilla CA wiki page that referred to the concept of “non-
unread,
Removal of 'non-disclosable intermediate certificates' language from Mozilla CA Wiki
All, We have removed the section of this Mozilla CA wiki page that referred to the concept of “non-
Feb 2
Dexter Castor Döpping
, …
Roman Fischer
8
Feb 2
HTTP request blocking by CAs for CRL, CPS, AIA caIssuers
I completely agree that CAs remain responsible to provide secure and available certificate status
unread,
HTTP request blocking by CAs for CRL, CPS, AIA caIssuers
I completely agree that CAs remain responsible to provide secure and available certificate status
Feb 2
Arabella Barks
Jan 29
Question on repurposing PublicCAs to PrivateCAs
Yo! mortals I noticed that DigiCert (after Symantec PKI acquisition) utilized the legacy VeriSign
unread,
Question on repurposing PublicCAs to PrivateCAs
Yo! mortals I noticed that DigiCert (after Symantec PKI acquisition) utilized the legacy VeriSign
Jan 29
Roger M Lambdin
,
Rollin Yu
5
Jan 21
Regarding the LiteSSL Certificate Issuance Authentication Vulnerability
The preliminary incident report has been published on Bugzilla: https://bugzilla.mozilla.org/show_bug
unread,
Regarding the LiteSSL Certificate Issuance Authentication Vulnerability
The preliminary incident report has been published on Bugzilla: https://bugzilla.mozilla.org/show_bug
Jan 21
Ben Wilson
Jan 5
Approval of Microsec's e-Szigno TLS Root CA 2023
All, Public discussion of the Microsec e-Szigno TLS Root CA 2023 root [1] occurred from November 7,
unread,
Approval of Microsec's e-Szigno TLS Root CA 2023
All, Public discussion of the Microsec e-Szigno TLS Root CA 2023 root [1] occurred from November 7,
Jan 5
Andrew Ayer
, …
Filippo Valsorda
8
12/13/25
Ongoing CT Logging Mistakes by CAs
I feel like it would be great if CAs that encoded invalid SCTs could proactively file incident
unread,
Ongoing CT Logging Mistakes by CAs
I feel like it would be great if CAs that encoded invalid SCTs could proactively file incident
12/13/25
Ben Wilson
12/12/25
Reflections on 2025 and Areas of Focus for 2026
Greetings, As we get to the end of 2025, it's time to reflect on the past year and to think about
unread,
Reflections on 2025 and Areas of Focus for 2026
Greetings, As we get to the end of 2025, it's time to reflect on the past year and to think about
12/12/25
Arabella Barks
, …
Aaron Gable
10
12/3/25
Why didn’t apple trust Wyvern2027h1 and sphinx2027h1 ctlog?
They're not non-compliant, and they don't need to be revoked. This is because, so far,
unread,
Why didn’t apple trust Wyvern2027h1 and sphinx2027h1 ctlog?
They're not non-compliant, and they don't need to be revoked. This is because, so far,
12/3/25
Arabella Barks
, …
Dimitris Zacharopoulos
5
11/26/25
Subject: Confusion/questions regarding SC-088v3
Hi Tobi, On 11/24/2025 1:03 PM, 'Tobias S. Josefowitz' via dev-secur...@mozilla.org
unread,
Subject: Confusion/questions regarding SC-088v3
Hi Tobi, On 11/24/2025 1:03 PM, 'Tobias S. Josefowitz' via dev-secur...@mozilla.org
11/26/25
Ben Wilson
11/23/25
Updated Value Statement Wiki Guidance
All, Based on a recent review of some of the Value Statements submitted by CA operator applicants, I
unread,
Updated Value Statement Wiki Guidance
All, Based on a recent review of some of the Value Statements submitted by CA operator applicants, I
11/23/25