[cabfpub] Allowing SHA-1 OCSP and CRL signatures past 2016

Gervase Markham gerv at mozilla.org
Wed Oct 26 02:41:57 MST 2016


On 26/10/16 01:26, Kirk Hall via Public wrote:
> I think we can treat this as a Maintenance Guideline to Sec. 7.1.3 of
> the BRs because we need to complete the adoption process by December
> 31. 

As Ryan comments, I think this is unwise. May I propose the alternative
solution of each root program agreeing that this change is reasonable?
You already have the assent of Mozilla, Google and (implicitly) Microsoft.

We can then pass a ballot after the IPR situation is sorted out but have
it apply retrospectively.

Hopefully between those two things, we shouldn't have a significant problem.

Gerv


More information about the Public mailing list