Hi Ben,
I fully support the goal of encouraging automation, but I'm a bit confused on this statement: "CA operators MUST disclose the URL for each such automation endpoint in the CCADB ..." I may be misinterpreting this to mean that the URL for an automation API is required to be published. In that case, I am hoping that the API details would not be required to be published, but instead only focus on the test websites.
I understand providing a URL for where test certificates will be published to prove that they are updated every 30 days, but not sure why there'd be a requirement for an "automation endpoint" URL to be published. In our case, while we use non-ACME automation for DCV and issuance/renewals, the endpoints are not publicly accessible and restricted only to our Subscribers. For this proposal, would it be enough to provide a URL to the test certificates that are renewed every 30 days or less?
Existing draft language:
CA operators MUST disclose the URL for each such automation endpoint in the CCADB and renew test certificates using such capability at least every 30 days to demonstrate compliance with these automation requirements.
Proposed draft language:
CA operators MUST renew test certificates using such capability at least every 30 days to demonstrate compliance with these automation requirements and disclose the URL for each test site in the CCADB.
Thank you,
Dustin
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
dev-security-po...@mozilla.org.
To view this discussion visit
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtaZSvQWjAjBseFN1A1TNGk5LD6_07xOm9LuL8T_8sLupmg%40mail.gmail.com.
Ben,
to better understand the rationale of the proposed requirement:
how does publishing a website whose TLS
certificate is renewed every 30 days demonstrate that the CA
actually performs such renewal in an automatic fashion?
TIA
Adriano
NOTICE: Pay attention - external email - Sender is dev-security-policy+bncBDIP...@mozilla.org
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/101e36dc-9b0c-4cd5-8536-b7c1c50feeac%40staff.aruba.it.