CA/Certificate Change Process: Difference between revisions

Jump to navigation Jump to search
Updated to match current process
(combine removal and disabling of a root into one section to remove duplicate information.)
(Updated to match current process)
Line 13: Line 13:
== Security Compromise ==
== Security Compromise ==


When a serious security concern is noticed, such as a major root compromise, it should be treated as a security-sensitive bug, and the [http://www.mozilla.org/projects/security/security-bugs-policy.html Mozilla Policy for Handling Security Bugs] should be followed.
When a serious security concern is noticed, such as a root compromise, it should be treated as a security-sensitive bug, and a [https://bugzilla.mozilla.org/enter_bug.cgi?product=NSS&component=CA%20Certificate%20Compliance&groups=crypto-core-security secure bug should be filed in Bugzilla].


To report a concern about certificates being issued by a CA in Mozilla's Program:
To report a concern about certificates being issued by a CA in Mozilla's Program:
Confirmed users, Administrators
5,526

edits

Navigation menu