On 20/04/18 14:30, Tim Shirley via dev-security-policy wrote:
> First of all, it's important to distinguish between the BR requirement, which is defined in terms of certificate *issuance* dates, and the value in the "Not Before" field. I'm guessing the "Not Before" value in this certificate is not the actual issuance timestamp, since it's unlikely it was issued right at the stroke of midnight. The CA is probably rounding, but we don't know if they're rounding up or down. But it would only be mis-issuance if the issuance occurred outside of the allowed time window. There's nothing I can see to show when the certificate was actually issued; it first showed up in CT logs on March 13, so we know it was issued on or before that, but that's all we know for sure about the issuance time.
>
> So what is the allowed time window according to the BRs? I'd argue that the intent was that it be >=. If you read the first bullet's "after" as >, then you have to also read the second bullet's "prior to" as <. So what rule applies to certificates issued ON March 1, 2018? Apparently none. Certainly that wasn't the intent, which is why I interpret the requirement as >=.
Indeed, I'm sure that wasn't the intent. However, if the BRs don't say
what the BRs intend to say, then the fault is with the BRs rather than
with the CA that adheres to what the BRs actually say. What the BRs
actually say is what matters, because that's what auditors will audit
against.
"after" is not the same thing as "on or after". "on or after" is used
elsewhere in the document to me >=, so TBH I think that reading "after"
as > is the only correct interpretation.
BTW, over in linting-land, we've already had this same discussion...
https://github.com/awslabs/certlint/pull/58
https://github.com/zmap/zlint/pull/195
>
https://lists.mozilla.org/listinfo/dev-security-policy
>
--
Rob Stradling
Senior Research & Development Scientist
Email: R...@ComodoCA.com
Bradford, UK
Office:
+441274730505
ComodoCA.com
This message and any files associated with it may contain legally
privileged, confidential, or proprietary information. If you are not the
intended recipient, you are not permitted to use, copy, or forward it,
in whole or in part without the express consent of the sender. Please
notify the sender by reply email, disregard the foregoing messages, and
delete it immediately.