Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Initial Incident Report Timeframe #270

Open
BenWilson-Mozilla opened this issue Aug 28, 2023 · 0 comments
Open

Initial Incident Report Timeframe #270

BenWilson-Mozilla opened this issue Aug 28, 2023 · 0 comments
Labels
3.0 Mozilla Root Store Policy version 3.0

Comments

@BenWilson-Mozilla
Copy link
Collaborator

Currently, MRSP section 2.4 says "an incident ... MUST be reported to Mozilla as soon as the CA operator is made aware". The CCADB's position on incident reporting (https://www.ccadb.org/cas/incident-report) is being modified, something to the effect that an incident report should be filed as soon as possible but no later than 72 hours after discovery. See https://github.com/mozilla/www.ccadb.org/compare/2be8d48..41e1892 Thus, this phrase in section 2.4 of the MDSP will likely need to be modified to be consistent with the CCADB Policy.

@BenWilson-Mozilla BenWilson-Mozilla added the 3.0 Mozilla Root Store Policy version 3.0 label Feb 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.0 Mozilla Root Store Policy version 3.0
Projects
None yet
Development

No branches or pull requests

1 participant