Confirmed users, Administrators
5,526
edits
(updated to correspond with current functionality) |
m (fixed typo) |
||
| Line 68: | Line 68: | ||
*** The root certificate is not enabled with the Websites trust bit. | *** The root certificate is not enabled with the Websites trust bit. | ||
* [[CA:ImprovingRevocation#Preload_Revocations_of_Intermediate_CA_Certificates|Revoked certificates]] that were capable of being used to issue new certificates, and which directly or transitively chain to their certificate(s) included in Mozilla’s CA Certificate Program and were not technically constrained as described in section 9 of [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ Mozilla's CA Certificate Inclusion Policy]. | * [[CA:ImprovingRevocation#Preload_Revocations_of_Intermediate_CA_Certificates|Revoked certificates]] that were capable of being used to issue new certificates, and which directly or transitively chain to their certificate(s) included in Mozilla’s CA Certificate Program and were not technically constrained as described in section 9 of [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ Mozilla's CA Certificate Inclusion Policy]. | ||
** Including revoked intermediate certificates that [[CA:ImprovingRevocation#When_To_Notify_Mozilla|should be added to OneCRL]] | |||
When the '''same exact intermediate certificate''' chains up to two included root certificates, the certificate data only needs to be included in Salesforce once. | When the '''same exact intermediate certificate''' chains up to two included root certificates, the certificate data only needs to be included in Salesforce once. | ||