mozilla / pkipolicy

Documents for Mozilla's PKI policies - certificate root program, etc.
52 stars 21 forks source link

Change year/annual to 365 days #243

Closed BenWilson-Mozilla closed 1 year ago

BenWilson-Mozilla commented 2 years ago

Re: annual publication of the CA's CP, CPS, CP/CPS, the wordings in both bullet 4 of MRSP section 3.3 and BR section 2.3 are ambiguous. Both “annually” and “once every year” should be read as every 365 days and not once per calendar year. This needs to be re-written to specify at least every 365 days.

BenWilson-Mozilla commented 2 years ago

I am considering whether this requirement should be changed more dramatically to have a period shorter than 365 days for updating the CP/CPSes that are applicable to TLS server certificate issuance. I'm not sure whether the same shortened period should apply to email certificates.

BenWilson-Mozilla commented 2 years ago

Posted to start a discussion of this on mdsp here - https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/JoyItinU9iQ/m/0QECoxA2CAAJ