CA:GovernmentCAs: Difference between revisions

Jump to navigation Jump to search
m
Line 69: Line 69:
* What would browsers do if a CA mis-issued a certifiate, but had a court-order to do so?
* What would browsers do if a CA mis-issued a certifiate, but had a court-order to do so?
** We would blacklist the false chains. Would potentially blacklist all of the CA's root certs. This would impact the CA's business. Government CAs do not have a commercial interest, so there is less downside for a Government CA being removed than for a commercial CA being removed.
** We would blacklist the false chains. Would potentially blacklist all of the CA's root certs. This would impact the CA's business. Government CAs do not have a commercial interest, so there is less downside for a Government CA being removed than for a commercial CA being removed.
* Some Government CAs are very slow to respond when changes are made to policy, such as technically constraining subordinate CAs and becoming compliant with the Baseline Requirements. https://wiki.mozilla.org/CA:Communications#January_2013_Responses


== Suggestions about what to do about Government CAs ==
== Suggestions about what to do about Government CAs ==
Confirmed users, Administrators
5,526

edits

Navigation menu