3 ms·
The root programs all allow for technical and procedural controls to meet the this criteria. There are technical controls beyond name constraints as well. Agai
by rmhrisk 14y ago
The root programs all allow for technical and procedural controls to meet the this criteria. There are technical controls beyond name constraints as well.
Again GlobalSign's policies do not allow the use of certificates that chain to our roots to be used for MiTM purposes (or other malicious use cases for that matter) and we have controls in place that protect against such things occurring.
- marshray 14y agoPerhaps if you described these technical controls in more detail we could reason about its security instead of by way of obscurity.
- rmhrisk 14y agoThey need to meet the same criteria we do, here are some starting points but its far from exaustive: http://www.mozilla.org/projects/security/certs/policy/ http://www.mozilla.org/projects/security/certs/policy/ http://social.technet.microsoft.com/wiki/contents/articles/3281.introduction-to-the-microsoft-root-certificate-program.aspx http://social.technet.microsoft.com/wiki/contents/articles/3... http://www.webtrust.org/homepage-documents/item27839.aspx http://www.webtrust.org/homepage-documents/item27839.aspx
- JoachimSchipper 14y agoThis is very comforting. After all, it's not like any CA "trusted" under those programs ever did Bad Things; certainly, these programs loudly warned about DigiNotar, TrustWave and TURKTRUST.