Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider Requiring Logging in Certificate Transparency #255

Open
BenWilson-Mozilla opened this issue Oct 5, 2022 · 1 comment
Open

Consider Requiring Logging in Certificate Transparency #255

BenWilson-Mozilla opened this issue Oct 5, 2022 · 1 comment

Comments

@BenWilson-Mozilla
Copy link
Collaborator

BenWilson-Mozilla commented Oct 5, 2022

Consider updating Mozilla's Root Store Policy to require that TLS server certificates be logged using Certificate Transparency.

@BenWilson-Mozilla BenWilson-Mozilla added the 2.9 Mozilla Root Store Policy v. 2.9 label Oct 5, 2022
@robstradling
Copy link

@BenWilson-Mozilla It's worth noting that no other Root Store Policy requires TLS server certificates to be logged to CT logs. Chrome and Apple both have separate CT Policies:

  • The Chrome CT Policy says:
    "The issuance of certificates that are not CT compliant is not considered mis-issuance or a violation of Chrome’s root program; such certificates will simply fail to validate in CT-enforcing versions of Chrome."
  • The Apple CT Policy doesn't explicitly state the Apple's root program's view on CT non-compliance, but I think the intent was to mirror Chrome's approach.

@WilsonKathleen WilsonKathleen changed the title Require Logging in Certificate Transparency Consider Requiring Logging in Certificate Transparency Oct 25, 2022
@BenWilson-Mozilla BenWilson-Mozilla removed the 2.9 Mozilla Root Store Policy v. 2.9 label Nov 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants