Gervase Markham
Fri May 22 08:53:16 UTC 2015

On 22/05/15 02:27, Ryan Sleevi wrote:
> As we discussed on the past week's call, I think it's very important to
> have the discussion first about what the information in the certificate
> is supposed to represent, before we can have any truly meaningful
> discussion about EV wildcards.

I think that's true. And also, to continue to use cloud providers as an
example, if we pick "just the cloud provider" or we pick "just the site
operator", then we have to say how we prevent the other party getting a
cert. Do we do it by restricting the validation methods, or by adding an
extra check by the CA, or by requiring the applicant to assert their
role in contract, or a different way altogether?


