You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The TLS BRs need to clearly state that it is not allowed to issue non-TLS leaf Certificates from server TLS-capable Issuing CAs, not even single-purpose "client authentication" leaf Certificates (end-entity certificates with just the id-kp-clientAuth EKU), which was allowed before SC-62.
The text was updated successfully, but these errors were encountered:
@dzacharo "not allowed to issue non-TLS leaf Certificates from server TLS-capable Issuing CAs" would disallow the issuance of OCSP Signer Certificates from Server TLS-capable Issuing CAs. I presume that's not your intent?
@dzacharo I'm removing the clean-up tag. While I agree this needs to be clarified, it might entail more work then just adding one or two sentenses, for example by what Rob highlighted. Happy to drive a separate ballot for this however. Feel free to comment if you disagree
The TLS BRs need to clearly state that it is not allowed to issue non-TLS leaf Certificates from server TLS-capable Issuing CAs, not even single-purpose "client authentication" leaf Certificates (end-entity certificates with just the
id-kp-clientAuth
EKU), which was allowed before SC-62.The text was updated successfully, but these errors were encountered: