Changes

Jump to: navigation, search

CA/Forbidden or Problematic Practices

483 bytes added, 09:19, 29 November 2013
no edit summary
CAs should be contactable by, and accept and act upon complaints made by, those relying on their assertions of identity. For CAs included in Mozilla, this will include being responsive to members of the general public, including people who have not purchased products from that CA.
 
===Backdating the notBefore date===
 
Certificates do not contain an issue timestamp, so it is not possible to be certain when they were issued. The notBefore date is the start of the certificate's validity range, and is set by the CA. It should be a reasonable reflection of the date on which the certificate was issued. Minor tweaking for technical compatibility reasons is accepted, but backdating certificates in order to avoid some deadline or code-enforced restriction is not.
== Other considerations when updating the CA Certificate Policy ==
Accountapprovers, antispam, confirm, emeritus
4,925
edits

Navigation menu