Policy 2.8: MRSP Issues List

86 views
Skip to first unread message

Ben Wilson

unread,
Feb 3, 2022, 4:57:08 PM2/3/22
to dev-secur...@mozilla.org
All,

Below is a list of the current MRSP issues for version 2.8. I believe we're getting closer to finalizing the language. 

 

There appear to be things to discuss for highlighted Issues #178 (Sunsetting SHA1), #219 (Requiring ETSI Auditors to be ACAB'c members), #226 (clarifying section 5.2), and #234 (CRL reason codes). 

 

Are there any others in the list that should still be considered open for discussion?

 

Also, besides the dates indicated below in the list, are there any other effective dates or compliance deadlines that should accompany any of these changes?

 

Thanks,


Ben

 

Github

Title                                   /                               Compliance Date

#131

Improve terminology and style / Immediate

#138

Make it clear that precertificates are covered by Mozilla policy / Immediate

#155

Describe actions Mozilla may take upon receipt of a qualified audit / Immediate

#178

Sunset SHA-1 in S/MIME Certificates / TBD

#184

Change Terminology from SSL to TLS / Immediate

#185

Require publication of outdated CA policy documents / Immediate

#195

Require public discussion when an organization receives a new subCA / Immediate

#198

Outline Policy Update Process / Immediate

#219

Require ETSI auditors to be ACAB-c members / Upon submission of next audit

#226

Update the incorrect extensions item in section 5.2 / Immediate

#227

Clarify Meaning of "CP/CPS" / Immediate

#228

Clarify technically-constrained sub-CA extended key usages / Immediate

#229

Disclose also TCSC to CCADB / July 1, 2022

#230

Clarifying Trust Transfer / Immediate

#233

Wiki page - process for reviewing externally operated CAs / Immediate

#234

Add Policy about CRL Revocation Reason Codes / September 1, 2022

#235

Require CCADB Disclosure of Full CRLs / October 1, 2022

 

 

Ben Wilson

unread,
Feb 9, 2022, 12:54:52 AM2/9/22
to dev-secur...@mozilla.org
All,
Here is a comparison between version 2.7.1 and proposed version 2.8 (without language yet for sunsetting SHA1 and requiring CRLReason codes).
Ben
Reply all
Reply to author
Forward
0 new messages