[cabfpub] Deprecating support for long-lived certificates

Rick Andrews Rick_Andrews at symantec.com
Mon Aug 26 18:32:35 UTC 2013


Gerv,

I'd like to understand if this represents a change in Mozilla's policy. Kathleen's previous statements seemed to indicate that the "effective date" for BR compliance was the first time the CA underwent their Web Trust for CAs audit after February 2013. Would this action push the "effective date" back to July 1, 2012?

-Rick

> -----Original Message-----
> From: public-bounces at cabforum.org [mailto:public-bounces at cabforum.org]
> On Behalf Of Gervase Markham
> Sent: Thursday, August 22, 2013 2:37 AM
> To: CABFPub
> Subject: Re: [cabfpub] Deprecating support for long-lived certificates
> 
> On 19/08/13 18:27, Ryan Sleevi wrote:
> > These checks, which will be landed into the Chromium repository in
> the
> > beginning of 2014, will reject as invalid any and all certificates
> > that have been issued after the Baseline Requirements Effective Date
> > of 2012-07-1 and which have a validity period exceeding the specified
> > maximum of 60 months.
> 
> We have filed a bug to consider taking the same action:
> https://bugzilla.mozilla.org/show_bug.cgi?id=908125
> 
> Gerv
> 
> _______________________________________________
> Public mailing list
> Public at cabforum.org
> https://cabforum.org/mailman/listinfo/public



More information about the Public mailing list