[cabfpub] Definition of an SSL certificate

Gervase Markham gerv at mozilla.org
Thu Feb 6 16:15:37 UTC 2014

On 19/12/13 16:05, Jeremy Rowley wrote:
> We are looking to clarify the scope of the BRs.  Right now the BR scope
> is very loose and subjective: “This version of the Requirements only
> addresses Certificates intended to be used for authenticating servers
>  accessible through the Internet.”

As a follow-up to this thread, I've opened a bug to discuss a possible

"Only accept certs for server TLS which have the TLS Server
Authentication EKU"

The bug has some interesting stats from the CT cert database about EKU


More information about the Public mailing list