CA/Certificate Change Process: Difference between revisions

→‎Remove or Disable a Root: Updated security bug link
m (→‎Remove or Disable a Root: Changed guidance)
(→‎Remove or Disable a Root: Updated security bug link)
Line 66: Line 66:
* No recent audit  
* No recent audit  


'''Important:''' Root changes that are motivated by a serious security concern such as a root compromise should be treated as a security-sensitive bug, and a [https://bugzilla.mozilla.org/enter_bug.cgi?product=CA%20Program&component=CA%20Certificate%20Compliance&groups=crypto-core-security secure bug filed in Bugzilla].
'''Important:''' Root changes that are motivated by a serious security concern such as a root compromise should be treated as a security-sensitive bug, and a [https://bugzilla.mozilla.org/enter_bug.cgi?product=CA%20Program&component=CA%20Security%20Vulnerability&groups=ca-program-security secure bug filed in Bugzilla].


The process for removing or disabling a root in NSS is as follows:
The process for removing or disabling a root in NSS is as follows:
# Initiate the request:
# Initiate the request:
#* [https://bugzilla.mozilla.org/enter_bug.cgi?&component=CA%20Certificate%20Root%20Program&product=CA%20Program&bug_severity=enhancement&short_desc=Remove%20%5Byour%20CA%27s%20name%5D%20root%20certificate%28s%29 File a bug in Bugzilla] with the following information:
#* [https://bugzilla.mozilla.org/enter_bug.cgi?&component=CA%20Certificate%20Root%20Program&product=CA%20Program&short_desc=Remove%20%5Byour%20CA%27s%20name%5D%20root%20certificate%28s%29 File a bug in Bugzilla] with the following information:
#** Product: CA Program
#** Product: CA Program
#** Component: CA Certificate Root Program  
#** Component: CA Certificate Root Program  
Confirmed users
525

edits