<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <br>
    <div class="moz-cite-prefix">On 14/10/2022 11:22 π.μ., Dimitris
      Zacharopoulos (HARICA) via Validation wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:01000183d596ac22-69b18f33-d87c-4254-86a2-95fc551405d4-000000@email.amazonses.com">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      The breakdown makes it clearer, thanks Doug. We just need to see
      how this will appear in the table via markdown.<br>
      <br>
      Dimitris.<br>
      <br>
      <div class="moz-cite-prefix">On 13/10/2022 11:05 μ.μ., Doug
        Beattie wrote:<br>
      </div>
      <blockquote type="cite"
cite="mid:SEZPR03MB6593396AE4149FC52709C106F0259@SEZPR03MB6593.apcprd03.prod.outlook.com">
        <meta http-equiv="Content-Type" content="text/html;
          charset=UTF-8">
        <meta name="Generator" content="Microsoft Word 15 (filtered
          medium)">
        <style>@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}div.WordSection1
        {page:WordSection1;}ol
        {margin-bottom:0in;}ul
        {margin-bottom:0in;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
        <div class="WordSection1">
          <p class="MsoNormal">Hi Dimitris,<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">I’d lean towards you option #2:<o:p></o:p></p>
          <ol type="1" start="2">
            <li class="MsoListParagraph"
style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:.25in;mso-list:l1
              level1 lfo5">Update 7.1.2.10.2, add the Attribute Type OU,
              and in the Presence column state "MUST NOT," except for
              Non-TLS Subordinate CA Certificates that meet the
              Certificate Profile described in section 7.1.2.3".<o:p></o:p></li>
          </ol>
          <p class="MsoNormal">Just a suggestion:<o:p></o:p></p>
          <ol type="1" start="2">
            <li class="MsoListParagraph"
style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:.25in;mso-list:l0
              level1 lfo6">Update 7.1.2.10.2, add the Attribute Type OU,
              and in the Presence column state:<o:p></o:p></li>
            <ul type="disc">
              <li class="MsoListParagraph"
style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:.25in;mso-list:l0
                level2 lfo6">MUST NOT for TLS Subordinate CA
                Certificates defined in section 7.1.2.3, <o:p></o:p></li>
              <li class="MsoListParagraph"
style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:.25in;mso-list:l0
                level2 lfo6">SHOULD NOT for all other CAs"<o:p></o:p></li>
            </ul>
          </ol>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
        </div>
      </blockquote>
    </blockquote>
    <br>
    Seeing no objections, I created
    <a class="moz-txt-link-freetext" href="https://github.com/cabforum/servercert/pull/398/files">https://github.com/cabforum/servercert/pull/398/files</a> with the
    proposed language. Let me know if the formatting (single line) works
    for everyone.<br>
    <br>
    Thanks,<br>
    Dimitris.<br>
  </body>
</html>