s...@gmx.ch
unread,Feb 28, 2020, 5:34:53 PM2/28/20You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to dev-secur...@lists.mozilla.org
Hi,
While I was connected to an IPv6-only network I noticed, that some CAs
(e.g. Amazon, DigiCert, GoDaddy, QuoVadis) do not provide IPv6 on their
CRL and OCSP endpoints. This means that certificate revocation does not
work if you have no IPv6 or, depending on your security policy (e.g.
require valid OCSP response), you get a lot of false positives.
Currently there is no section in the CA BR that requires dual-stack for
CRL/OCSP. However, IPv6-only environments do exist and they will
increase in future. So I wonder if you're aware of this issue and if
there are any plans for mitigation.
Best regards,