4 ms·
Followed up yesterday with: "Certificate Authorities have highly trusted roles in the internet ecosystem and it is unacceptable for a CA to be closely tied, th
by charleyablaze 4y ago
Followed up yesterday with:
"Certificate Authorities have highly trusted roles in the internet ecosystem and it is unacceptable for a CA to be closely tied, through ownership and operation, to a company engaged in the distribution of malware. Trustcor’s responses via their Vice President of CA operations further substantiates the factual basis for Mozilla’s concerns.
[...]
Our assessment is that the concerns about TrustCor have been substantiated and the risks of TrustCor’s continued membership in Mozilla’s Root Program outweighs the benefits to end users.
In line with our earlier communication, we intend to take the following actions:
1. Set “Distrust for TLS After Date” and “Distrust for S/MIME After Date” to November 30, 2022, for the 3 TrustCor root certificates (TrustCor RootCert CA-1, TrustCor ECA-1, TrustCor RootCert CA-2) that are currently included in Mozilla’s root store.
2. Remove those root certificates from Mozilla’s root store after the existing end-entity TLS certificates have expired."
- DonHopkins 4y ago>Trustcor’s responses via their Vice President of CA operations further substantiates the factual basis for Mozilla’s concerns. So Mozilla is flatly stating that Rachel's Gish galloping bullshit responses in the discussion were a significant part of the reason they don't trust her. She should have just followed a good lawyer's advice and kept her mouth shut, because she made her own problems much worse with her own words.