Changes

Jump to: navigation, search

CA/Certinomis Issues

543 bytes added, 20:42, 23 April 2019
Issue F.3: Inadequate Controls on Production Testing: Add response to new test cert
On 17-April, 2019, [https://crt.sh/?sha256=97C78F92745645FE7ABC5A531C27F4C29D54F193563FB2035C01A0BE74CA3BBA another certificate] was [https://bugzilla.mozilla.org/show_bug.cgi?id=1496088#c20 reported]. This one contains "O=Entreprise TEST" and was issued in January, after [https://bugzilla.mozilla.org/show_bug.cgi?id=1496088#c11 Certinomis stated] that such issuance had been stopped.
 
CERTINOMIS RESPONSE (Summary): In November, certs requested from the "Front Office" system for "O-Entreprise test" were moved to non-PTC, but requests were still possible via the "Back Office" system, which is how this new certificate was requested. As of 25-April, the ability to request certificates via the "Back Office" system was disabled. The certificate was revoked and Certinomis confirmed that all other "test" certificates have been revoked or are expired. ([https://bugzilla.mozilla.org/show_bug.cgi?id=1496088#c21 full response])
==== Issue F.4: Validity > 825 Days ====
136
edits

Navigation menu