Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ensure CAs are collecting sufficient data to investigate CAA errors #356

Open
CBonnell opened this issue Mar 31, 2022 · 2 comments
Open

Comments

@CBonnell
Copy link
Member

https://groups.google.com/d/msg/mozilla.dev.security.policy/7AcHi_MgKWE/-E3z-ifLBQAJ

The current requirement is:

"The CA SHALL log all actions taken, if any, consistent with its processing
practice."

Perhaps it needs to be more detailed about the minimum logging necessary, to help diagnose CAA checking failures and possible misissuances.

@CBonnell CBonnell moved this to Backlog in Validation Aug 1, 2022
@CBonnell CBonnell changed the title Improve CAA logging requirements Ensure CAs are collecting sufficient data to investigate CAA errors Aug 1, 2022
@CBonnell
Copy link
Member Author

CBonnell commented Aug 1, 2022

This item was reviewed at the 2022-07-28 meeting.

There was agreement that we should revisit at a later date in light of the passage of SC-51 to see what (if any), concrete improvements can be derived from this item.

@wthayer
Copy link
Contributor

wthayer commented Nov 5, 2023

Discussed at 11/2/23 Validation subcommittee meeting. it’s unclear if this is for CA’s own investigations, or for the forum to use the data. It was suggested this this task should better define 'errors outside the CA's infrastructure'.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Backlog
Development

No branches or pull requests

2 participants