mozilla / pkipolicy

Documents for Mozilla's PKI policies - certificate root program, etc.
50 stars 21 forks source link

Proof of Possession of Private Key for SMIME #215

Open BenWilson-Mozilla opened 4 years ago

BenWilson-Mozilla commented 4 years ago

Corey Bonnell noted on m.d.s.p. on 22-May-2020 that we should consider "mandate PoP for S/MIME certificate issuance. Lack of checking for S/MIME would present more concrete security concerns" than TLS.

RufusJWB commented 4 years ago

I totally support that!

bitcynth commented 4 years ago

Seems like a very reasonable idea to me

BenWilson-Mozilla commented 3 years ago

I've mentioned this here: https://archive.cabforum.org/pipermail/smcwg-public/2020-December/000072.html