CA/Certificate Change Process: Difference between revisions

→‎Security Compromise: Changed URL to Bugzilla
(Changed Bugzilla Product from NSS to CA Program per Bugzilla Bug #1799573)
(→‎Security Compromise: Changed URL to Bugzilla)
Line 13: Line 13:
== Security Compromise ==
== Security Compromise ==


When a serious security concern is noticed, such as a root compromise, it should be treated as a security-sensitive bug, and a [https://bugzilla.mozilla.org/enter_bug.cgi?product=CA%20Program&component=CA%20Certificate%20Compliance&groups=crypto-core-security secure bug should be filed in Bugzilla].
When a serious security concern is noticed, such as a root compromise, it should be treated as a security-sensitive bug, and a [https://bugzilla.mozilla.org/enter_bug.cgi?product=CA%20Program&component=CA%20Security%20Vulnerability&groups=ca-program-security secure bug should be filed in Bugzilla].


To report a concern about certificates being issued by a CA in Mozilla's Program:
To report a concern about certificates being issued by a CA in Mozilla's Program:
Line 19: Line 19:
* https://bugzilla.mozilla.org/enter_bug.cgi?product=CA%20Program&component=CA%20Certificate%20Compliance&version=other
* https://bugzilla.mozilla.org/enter_bug.cgi?product=CA%20Program&component=CA%20Certificate%20Compliance&version=other


Open CA Mis-Issuance bugs: https://wiki.mozilla.org/CA/Incident_Dashboard
Open CA Mis-Issuance and other compliance bugs: https://wiki.mozilla.org/CA/Incident_Dashboard


== Add a Trust Bit ==
== Add a Trust Bit ==
Confirmed users
518

edits