Bug 1877388 Comment 25 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

(In reply to Arnold Essing from comment #23)
> We had several escalations and displeased customers and even lost a few in the process. So we did actually take a very uncomfortable position with our customers and also pushed those that claimed to not have enough time. However, we can not make an ultimate statement that there will be no more delayed revocations. The Mozilla wiki itself states that this decision must be based on the risks imposed on the parties: “It is our position that your CA is ultimately responsible for deciding if the harm caused by following the requirements of the Baseline Requirements outweighs the risks that are passed on to individuals who rely on the web PKI by choosing not to meet this requirement.”        
> 
> However, we are doing everything we can to avoid these situations by optimizing processes together with our customers, promoting automation and so on. Speaking of which:
> We finalized our action item tasks “slides for a training with regard to automation” and “self-assessment for Enterprise RAs”. We approached the first customers with the request to fill out the self-assessment in a timely manner and plan on using their feedback for some fine-tuning. Afterwards, the self-assessment will be distributed to all remaining customers. Based on the results, we will then approach individual customers in regard to automation of certificate management.
> Unless there are comments in the next few days, we would like to request to close this bug.

First, thank you for upholding your commitment to the BRs and the integrity of the WebPKI even when it was uncomfortable and had negative consequences for your business. It is appreciated!

The action items listed here, however, seem to stop at "we will try" rather than "we will ensure". You describe outreach and assessment, which are certainly good, but it seems like Telekom Security should be working to ensure that they do not have any certificates issued in the future to subscribers who cannot accommodate the revocation deadlines set forth in the BRs. Will Telekom Security ensure that subscribers are assessed for this capability before certificates are issued to them? Will you update your CPS (1.4.2) and associated documentation/notices to indicate that the certificates are not appropriate for use in circumstances where a 24-hour revocation may be required in an emergency, and a 5-hour revocation required during the course of normal business?
(In reply to Arnold Essing from comment #23)
> We had several escalations and displeased customers and even lost a few in the process. So we did actually take a very uncomfortable position with our customers and also pushed those that claimed to not have enough time. However, we can not make an ultimate statement that there will be no more delayed revocations. The Mozilla wiki itself states that this decision must be based on the risks imposed on the parties: “It is our position that your CA is ultimately responsible for deciding if the harm caused by following the requirements of the Baseline Requirements outweighs the risks that are passed on to individuals who rely on the web PKI by choosing not to meet this requirement.”        
> 
> However, we are doing everything we can to avoid these situations by optimizing processes together with our customers, promoting automation and so on. Speaking of which:
> We finalized our action item tasks “slides for a training with regard to automation” and “self-assessment for Enterprise RAs”. We approached the first customers with the request to fill out the self-assessment in a timely manner and plan on using their feedback for some fine-tuning. Afterwards, the self-assessment will be distributed to all remaining customers. Based on the results, we will then approach individual customers in regard to automation of certificate management.
> Unless there are comments in the next few days, we would like to request to close this bug.

First, thank you for upholding your commitment to the BRs and the integrity of the WebPKI even when it was uncomfortable and had negative consequences for your business. It is appreciated!

The action items listed here, however, seem to stop at "we will try" rather than "we will ensure". You describe outreach and assessment, which are certainly good, but it seems like Telekom Security should be working to ensure that they do not have any certificates issued in the future to subscribers who cannot accommodate the revocation deadlines set forth in the BRs. Will Telekom Security ensure that subscribers are assessed for this capability before certificates are issued to them? Will you update your CPS (1.4.2) and associated documentation/notices to indicate that the certificates are not appropriate for use in circumstances where a 24-hour revocation may be required in an emergency, and a 5-day revocation required during the course of normal business?

Back to Bug 1877388 Comment 25