[cabfpub] Definition of an SSL certificate

Gervase Markham gerv at mozilla.org
Thu Feb 6 16:15:37 UTC 2014


On 19/12/13 16:05, Jeremy Rowley wrote:
> We are looking to clarify the scope of the BRs.  Right now the BR scope
> is very loose and subjective: “This version of the Requirements only
> addresses Certificates intended to be used for authenticating servers
>  accessible through the Internet.”

As a follow-up to this thread, I've opened a bug to discuss a possible
change:

"Only accept certs for server TLS which have the TLS Server
Authentication EKU"
https://bugzilla.mozilla.org/show_bug.cgi?id=968817

The bug has some interesting stats from the CT cert database about EKU
usage.

Gerv



More information about the Public mailing list