Changes

Jump to: navigation, search

CA/e-commerce-monitoring Issues

268 bytes added, 5 June
m
Certificate issued with two pre-certificates: Added quote
https://bugzilla.mozilla.org/show_bug.cgi?id=1830536
Related to Bug # 1815534, it was also discovered that in an attempt to obtain a sufficient number of SCTs, ECM’s CT component submitted two pre-certificates for a single final certificate (all with the same serial number). These two incidents exposed a lack of internal verification processes and automated checks for changes to CT log servers. ECM committed noted that "certificate transparency has brought a new dimension as described in the present report – the fact that also an assumed-to providing better “lessons learned” -exist-certificate is in scope by virtue of Mozilla Root Store Policy 5.4. This had not been properly taken into account in our interpretation and enhanced transparency to the communitymeasures, respectively." https://bugzilla.mozilla.org/show_bug.cgi?id=1830536#c1
'''Issues:''' Certificate Misissuance; Incident Reporting
Confirm
385
edits

Navigation menu