Hacker News new | past | comments | ask | show | jobs | submit login

Oh let me guess how this goes:

> Ballot 161 – Notification of incorrect issuance

> In the event that a CA issues a certificate in violation of these requirements, the CA SHALL publicly disclose a report within one week of becoming aware of the violation. A link to the report SHALL simultaneously be sent to incidents@cabforum.org.

> From the CAs, there were 0 YES votes, 14 NO votes and 5 Abstentions

> From the Browsers, there were 3 YES votes, 0 NO votes and 0 Abstentions.

sigh




The ballot was a bit more nuanced than it seems. 1) Browsers already require reporting of mis-issuance directly to them. Mozilla requires a public bug list and 2) There was insufficient clarity in the ballot about "mis-issuance". Plus with crt.sh, this information is already available in one general location, which made the reporting requirement of everything seem a bit redundant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: