CA:ImprovingRevocation: Difference between revisions

Line 67: Line 67:


* Process Change: Update the [https://wiki.mozilla.org/CA:Information_checklist Root Inclusion Checklist] to provide information about how to manually test CRLs in NSS using [https://developer.mozilla.org/en-US/docs/NSS/tools/NSS_Tools_crlutil crlutil].
* Process Change: Update the [https://wiki.mozilla.org/CA:Information_checklist Root Inclusion Checklist] to provide information about how to manually test CRLs in NSS using [https://developer.mozilla.org/en-US/docs/NSS/tools/NSS_Tools_crlutil crlutil].
=== No EV Treatment when OCSP Fails or Not Provided ===
EV Treatment will not be given when the OCSP response fails or cannot be retrieved for end-entity and intermediate certificates.
* Release: Target is mozilla25
* Discussion: [https://groups.google.com/d/msg/mozilla.dev.security.policy/mYKaLIcP70I/255h8y4-0YYJ mozilla.dev.security.policy]
* Code Change: {{Bug|585122#c34}}
* Dependencies: OCSP Stapling
** Some sites that are currently receiving EV treatment may stop getting EV treatment. If that happens, check that the OCSP URI is in the AIA of the end-entity and intermediate certificates (unless stapled OCSP response is provided), and that the OCSP responses are correctly being returned.
* Policy Change: None. The EV guidelines already require OCSP.
* Process Change: None. We already check for this for root inclusion/changes requests.


=== ''Change Name'' ===
=== ''Change Name'' ===
Confirmed users, Administrators
5,526

edits