Groups
Conversations
All groups and messages
Send feedback to Google
Help
Training
Sign in
Groups
dev-security-policy@mozilla.org
Conversations
About
Sort By Relevance
Sort By Date
1–30 of many
Ben Wilson
, …
Clint Wilson
14
1/23/23
Policy 2.8.1: MRSP Issue #256: Requirement that Partitioned CRLs include an Issuing Distribution Point extension
the Apple
Policy
: Effective October 1, 2022, CA providers must populate the CCADB fields under "Pertaining to Certificates Issued by This CA" with either the CRL Distribution
unread,
Policy 2.8.1: MRSP Issue #256: Requirement that Partitioned CRLs include an Issuing Distribution Point extension
the Apple
Policy
: Effective October 1, 2022, CA providers must populate the CCADB fields under "Pertaining to Certificates Issued by This CA" with either the CRL Distribution
1/23/23
Ben Wilson
,
Corey Bonnell
2
12/8/22
Policy 2.8.1: MRSP Issue #251: Full CRL Publication Requirements
information,
policy
should be amended such that: 1. The location(s) of CRL(s) for dormant CAs MUST be disclosed prior to issuing any certificates (ie, making the CA "active"
unread,
Policy 2.8.1: MRSP Issue #251: Full CRL Publication Requirements
information,
policy
should be amended such that: 1. The location(s) of CRL(s) for dormant CAs MUST be disclosed prior to issuing any certificates (ie, making the CA "active"
12/8/22
Ben Wilson
,
Corey Bonnell
2
12/7/22
Policy 2.8.1: MRSP Issue #253: CAs MUST specify BR 3.2.2.4 Methods
Store >
Policy
> . > In Mozilla's PKI
Policy
repository in GitHub, Issue #253 > , it is suggested that > we replace lower case "must" and uppercase "
unread,
Policy 2.8.1: MRSP Issue #253: CAs MUST specify BR 3.2.2.4 Methods
Store >
Policy
> . > In Mozilla's PKI
Policy
repository in GitHub, Issue #253 > , it is suggested that > we replace lower case "must" and uppercase "
12/7/22
Ben Wilson
,
Aaron Poulsen
5
11/22/22
Policy 2.8.1: Candidate Issues to Address in MRSP v. 2.8.1
Root Store
Policy
, identify any potential implementation-scheduling problems, and then communicate those back to the list. Thanks, Ben On Tue, Nov 22, 2022 at 12:27 PM Aaron Poulsen
unread,
Policy 2.8.1: Candidate Issues to Address in MRSP v. 2.8.1
Root Store
Policy
, identify any potential implementation-scheduling problems, and then communicate those back to the list. Thanks, Ben On Tue, Nov 22, 2022 at 12:27 PM Aaron Poulsen
11/22/22
Ben Wilson
, …
Matthias van de Meent
7
11/18/22
Policy 2.8.1: MRSP Issue #249: Clarification re: all CPs and CPSes
that applicable
policy
and practice documents can be retrieved for the R1 hierarchy for the period 1995 - 2020; for the R2 hierarchy, for the period from 2005 - 2030; and for the R3 hierarchy
unread,
Policy 2.8.1: MRSP Issue #249: Clarification re: all CPs and CPSes
that applicable
policy
and practice documents can be retrieved for the R1 hierarchy for the period 1995 - 2020; for the R2 hierarchy, for the period from 2005 - 2030; and for the R3 hierarchy
11/18/22
Ben Wilson
, …
Ryan Dickson
10
11/17/22
Policy 2.8.1: MRSP Issue #243: Update periods for CPs and CPSes
on these
policy
documents, in part, to evaluate that CAs are upholding their commitments and operating services as expected. We also use them when assessing incidents (to understand
unread,
Policy 2.8.1: MRSP Issue #243: Update periods for CPs and CPSes
on these
policy
documents, in part, to evaluate that CAs are upholding their commitments and operating services as expected. We also use them when assessing incidents (to understand
11/17/22
Ben Wilson
11/15/22
Policy 2.8.1: MRSP Issue #257: Requiring CAs to follow Discussions on the CCADB Public List
Mozilla PKI
Policy
repository on GitHub. The proposed language for the last paragraph of section 2.1 of the Mozilla Root Store
Policy
is as follows: "CA operators MUST follow
unread,
Policy 2.8.1: MRSP Issue #257: Requiring CAs to follow Discussions on the CCADB Public List
Mozilla PKI
Policy
repository on GitHub. The proposed language for the last paragraph of section 2.1 of the Mozilla Root Store
Policy
is as follows: "CA operators MUST follow
11/15/22
Ben Wilson
, …
Ryan Sleevi
51
4/29/22
Policy 2.8: Final Review of MRSP v. 2.8
? Version
2.8
has been finalized and is going through the publication process today, which I was going to announce when it is up on the Mozilla website. Thanks, Ben On Thu, Apr 28, 2022
unread,
Policy 2.8: Final Review of MRSP v. 2.8
? Version
2.8
has been finalized and is going through the publication process today, which I was going to announce when it is up on the Mozilla website. Thanks, Ben On Thu, Apr 28, 2022
4/29/22
Ben Wilson
4/14/22
Policy 2.8: Draft April 2022 CA Communication Survey
Root Store
Policy
v.
2.8
that I will be sending through the CCADB mailer to all CAs in the Mozilla program. I also have a cover letter for the CA communication, which is boilerplate similar
unread,
Policy 2.8: Draft April 2022 CA Communication Survey
Root Store
Policy
v.
2.8
that I will be sending through the CCADB mailer to all CAs in the Mozilla program. I also have a cover letter for the CA communication, which is boilerplate similar
4/14/22
Ben Wilson
, …
Ryan Sleevi
40
4/7/22
Policy 2.8: MRSP Issue #219: Require ETSI auditors to be ACAB-c members
security-
policy
@mozilla.org" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to dev-security-
policy
+unsubscribe@mozilla
unread,
Policy 2.8: MRSP Issue #219: Require ETSI auditors to be ACAB-c members
security-
policy
@mozilla.org" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to dev-security-
policy
+unsubscribe@mozilla
4/7/22
Ben Wilson
4/4/22
Policy 2.8: MRSP Issue #238: Clarify that CAs can generate their own keys
v.
2.8
. Currently, section 5.2 of the MRSP says, "CAs MUST NOT generate the key pairs for end-entity certificates that have an EKU extension containing the KeyPurposeIds id-
unread,
Policy 2.8: MRSP Issue #238: Clarify that CAs can generate their own keys
v.
2.8
. Currently, section 5.2 of the MRSP says, "CAs MUST NOT generate the key pairs for end-entity certificates that have an EKU extension containing the KeyPurposeIds id-
4/4/22
Ben Wilson
, …
Ryan Sleevi
18
4/4/22
Policy 2.8: MRSP Issue #185: Require publication of outdated CA policy documents
sequence of
policy
documents for that same period. >> >> This
policy
change doesn't fully require the "birth certificate" approach >> (although
unread,
Policy 2.8: MRSP Issue #185: Require publication of outdated CA policy documents
sequence of
policy
documents for that same period. >> >> This
policy
change doesn't fully require the "birth certificate" approach >> (although
4/4/22
Ben Wilson
, …
Ryan Sleevi
4
3/28/22
Policy 2.8: MRSP Issue #227: Clarify Meaning of "CP/CPS"
a Certificate
Policy
and/or Certification > Practice Statement". (Here, implementing the conjunctions "and" and "or" > get messy.) Currently
unread,
Policy 2.8: MRSP Issue #227: Clarify Meaning of "CP/CPS"
a Certificate
Policy
and/or Certification > Practice Statement". (Here, implementing the conjunctions "and" and "or" > get messy.) Currently
3/28/22
Ben Wilson
3/25/22
Policy 2.8: MRSP Issue #234: Add Policy about CRL Revocation Reason Codes
Root Store
Policy
. It can be reviewed here in the current draft version of MRSP v.
2.8
- see https://github.com/mozilla/pkipolicy/compare/master...BenWilson-Mozilla:
2.8
or
unread,
Policy 2.8: MRSP Issue #234: Add Policy about CRL Revocation Reason Codes
Root Store
Policy
. It can be reviewed here in the current draft version of MRSP v.
2.8
- see https://github.com/mozilla/pkipolicy/compare/master...BenWilson-Mozilla:
2.8
or
3/25/22
Ben Wilson
3
3/18/22
Policy 2.8: MRSP Issue 195: Require public discussion when an organization receives a new subCA
v.
2.8
and the wiki page with language that allows replacement of existing CA certificates without requiring the public discussion process. For discussion purposes, let's assume
unread,
Policy 2.8: MRSP Issue 195: Require public discussion when an organization receives a new subCA
v.
2.8
and the wiki page with language that allows replacement of existing CA certificates without requiring the public discussion process. For discussion purposes, let's assume
3/18/22
Ben Wilson
, …
Francesc Ferrer
30
3/11/22
Policy 2.8: MRSP Issue #178: Sunset SHA1
security-
policy
group, Consorci AOC supports banning SHA-1 across the board. We no longer support SHA-1 signatures for services related to CAs trusted by Mozilla, in our situation
unread,
Policy 2.8: MRSP Issue #178: Sunset SHA1
security-
policy
group, Consorci AOC supports banning SHA-1 across the board. We no longer support SHA-1 signatures for services related to CAs trusted by Mozilla, in our situation
3/11/22
Ben Wilson
, …
Corey Bonnell
11
2/10/22
Policy 2.8: MRSP Issue #229: Disclose Technically Constrained CAs in the CCADB
of this
Policy
”. As an aside, it appears that a requirement to audit TCSCs was included in the commit from two days ago: https://github.com/BenWilson-Mozilla/pkipolicy/commit
unread,
Policy 2.8: MRSP Issue #229: Disclose Technically Constrained CAs in the CCADB
of this
Policy
”. As an aside, it appears that a requirement to audit TCSCs was included in the commit from two days ago: https://github.com/BenWilson-Mozilla/pkipolicy/commit
2/10/22
Ben Wilson
2
2/9/22
Policy 2.8: MRSP Issues List
proposed version
2.8
(without language yet for sunsetting SHA1 and requiring CRLReason codes). https://github.com/mozilla/pkipolicy/compare/master...BenWilson-Mozilla
unread,
Policy 2.8: MRSP Issues List
proposed version
2.8
(without language yet for sunsetting SHA1 and requiring CRLReason codes). https://github.com/mozilla/pkipolicy/compare/master...BenWilson-Mozilla
2/9/22
Ben Wilson
, …
Ryan Sleevi
4
2/3/22
Policy 2.8: MRSP Issue #232: Add policy about old root certificates
security-
policy
@mozilla.org wrote: > >> Hi Ben, >> >> >> >> I'm not against removing old roots from the trust store, but is using the >
unread,
Policy 2.8: MRSP Issue #232: Add policy about old root certificates
security-
policy
@mozilla.org wrote: > >> Hi Ben, >> >> >> >> I'm not against removing old roots from the trust store, but is using the >
2/3/22
Ben Wilson
, …
Dimitris Zacharopoulos
18
2/3/22
Policy 2.8: MRSP Issue #228: Clarify technically-constrained sub-CA EKUs
of this
policy
also >> apply to technically constrained intermediate certificates.* >> >> *If the certificate includes the id-kp-emailProtection extended
unread,
Policy 2.8: MRSP Issue #228: Clarify technically-constrained sub-CA EKUs
of this
policy
also >> apply to technically constrained intermediate certificates.* >> >> *If the certificate includes the id-kp-emailProtection extended
2/3/22
Ben Wilson
, …
Ryan Sleevi
7
2/3/22
Policy 2.8: MRSP Issue #226: Update the incorrect extensions item in section 5.2
security-
policy
@mozilla.org < >>>> dev-security-
policy
@mozilla.org> >>>> *Sent:* Thursday, January 13, 2022 8:12 PM >>>> *
unread,
Policy 2.8: MRSP Issue #226: Update the incorrect extensions item in section 5.2
security-
policy
@mozilla.org < >>>> dev-security-
policy
@mozilla.org> >>>> *Sent:* Thursday, January 13, 2022 8:12 PM >>>> *
2/3/22
Ben Wilson
,
Ryan Sleevi
10
2/2/22
Policy 2.8: MRSP Issue #155: Describe actions Mozilla may take upon receipt of a qualified audit
of this
policy
, This is a totally accurate statement, but doesn't seem to be the same as originally envisioned in the bugs? That is, imagine a WebTrust auditor (or an ACAB'c
unread,
Policy 2.8: MRSP Issue #155: Describe actions Mozilla may take upon receipt of a qualified audit
of this
policy
, This is a totally accurate statement, but doesn't seem to be the same as originally envisioned in the bugs? That is, imagine a WebTrust auditor (or an ACAB'c
2/2/22
Ben Wilson
1/24/22
Policy 2.8: MRSP Issue #198: Outline Policy Update Process
Root Store
Policy
(MRSP). This is Github Issue #198 . Here is a redline: https://github.com/BenWilson-Mozilla/pkipolicy/commit/2ba1ff1f134db1c600c04805c33d2fb903ce32a9
unread,
Policy 2.8: MRSP Issue #198: Outline Policy Update Process
Root Store
Policy
(MRSP). This is Github Issue #198 . Here is a redline: https://github.com/BenWilson-Mozilla/pkipolicy/commit/2ba1ff1f134db1c600c04805c33d2fb903ce32a9
1/24/22
Ben Wilson
,
Andrew Ayer
2
1/16/22
Policy 2.8: MRSP Issue #138: Make it clear that RFC 9162 precertificates are covered by Mozilla policy
general Mozilla
policy
needs to reference RFC 6962 because it describes the system that is actually deployed. 2. When a Precertificate Signing Certificate is used, the issuer of a
unread,
Policy 2.8: MRSP Issue #138: Make it clear that RFC 9162 precertificates are covered by Mozilla policy
general Mozilla
policy
needs to reference RFC 6962 because it describes the system that is actually deployed. 2. When a Precertificate Signing Certificate is used, the issuer of a
1/16/22
Ben Wilson
1/13/22
Policy 2.8: MRSP Issue #131: Improve terminology and style
Root Store
Policy
(MSRP), version
2.8
, to be published in 2022. (See https://github.com/mozilla/pkipolicy/labels/
2.8
) This is Github Issue #131 . - It changes "CA"
unread,
Policy 2.8: MRSP Issue #131: Improve terminology and style
Root Store
Policy
(MSRP), version
2.8
, to be published in 2022. (See https://github.com/mozilla/pkipolicy/labels/
2.8
) This is Github Issue #131 . - It changes "CA"
1/13/22
Ben Wilson
1/13/22
Policy 2.8: MRSP Issue #184: Change Terminology from SSL to TLS
Root Store
Policy
. Also, when talking about trust bits, the term "SSL" is changed to "websites". This is Github Issue #184 . Here is a redline: https://github
unread,
Policy 2.8: MRSP Issue #184: Change Terminology from SSL to TLS
Root Store
Policy
. Also, when talking about trust bits, the term "SSL" is changed to "websites". This is Github Issue #184 . Here is a redline: https://github
1/13/22
Ben Wilson
, …
Aaron Gable
5
1/6/22
Policy 2.8: MRSP Issue #235: Require CCADB Disclosure of Full CRLs (or equivalent JSON array) for CRLite
security-
policy
@mozilla.org wrote: > >> Is there a preference for which provides the greatest clarity to CAs >> (thinking especially of those that haven't
unread,
Policy 2.8: MRSP Issue #235: Require CCADB Disclosure of Full CRLs (or equivalent JSON array) for CRLite
security-
policy
@mozilla.org wrote: > >> Is there a preference for which provides the greatest clarity to CAs >> (thinking especially of those that haven't
1/6/22
Ben Wilson
, …
Wayne Thayer
13
12/9/21
Policy 2.8: MRSP Issue #233: Wiki page documenting process for reviewing externally operated subordinate CAs
security-
policy
@mozilla.org wrote: >>> >>>> > Is it necessary to start a new discussion every time a new CA >>>> Certificate is about to be
unread,
Policy 2.8: MRSP Issue #233: Wiki page documenting process for reviewing externally operated subordinate CAs
security-
policy
@mozilla.org wrote: >>> >>>> > Is it necessary to start a new discussion every time a new CA >>>> Certificate is about to be
12/9/21
Ben Wilson
,
Kathleen Wilson
4
11/17/21
Policy 2.8: Candidate Issues to Address in MRSP v. 2.8
in version
2.8
of the Mozilla Root Store
Policy
. *Discussion will remain open until 1-Dec-2021 * #233 - Editing Process for Review and Approval of Externally Operated Subordinate
unread,
Policy 2.8: Candidate Issues to Address in MRSP v. 2.8
in version
2.8
of the Mozilla Root Store
Policy
. *Discussion will remain open until 1-Dec-2021 * #233 - Editing Process for Review and Approval of Externally Operated Subordinate
11/17/21
Ben Wilson
11/10/21
Policy 2.8: MRSP Issue #230: Clarifying Trust Transfer
Root Store
Policy
(MSRP), version
2.8
, to be published in 2022. (See https://github.com/mozilla/pkipolicy/labels/
2.8
) This is Github Issue #230 . The proposal is to change "
unread,
Policy 2.8: MRSP Issue #230: Clarifying Trust Transfer
Root Store
Policy
(MSRP), version
2.8
, to be published in 2022. (See https://github.com/mozilla/pkipolicy/labels/
2.8
) This is Github Issue #230 . The proposal is to change "
11/10/21