Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MPIC - Clarify when a CA is or is not allowed to issue #557

Open
XolphinMartijn opened this issue Oct 23, 2024 · 1 comment
Open

MPIC - Clarify when a CA is or is not allowed to issue #557

XolphinMartijn opened this issue Oct 23, 2024 · 1 comment
Labels
clean-up Items for future clean-up ballot

Comments

@XolphinMartijn
Copy link
Member

"The CA MUST NOT proceed with certificate issuance if the number of non-corroborations is greater than allowed in the Quorum Requirements table and if the remote Network Perspectives that do corroborate the determinations made by the Primary Network Perspective do not fall within the service regions of at least two (2) distinct Regional Internet Registries."

Should the ”and” in ”and if the remote” not be an ”or”? Otherwise, it seems to me a CA might be allowed to issue even with 3 non-corroborations, as long as all corroborations are at least in two different RIRs.

Having discussed with @ryancdickson, suggesting using:

The CA MUST only proceed with certificate issuance if the requirements defined in Quorum Requirements Table are satisfied, and
the remote Network Perspectives that corroborate the Primary Network Perspective fall within the service regions of at least two (2) distinct Regional Internet Registries.

@XolphinMartijn XolphinMartijn added the clean-up Items for future clean-up ballot label Oct 23, 2024
Copy link

This issue was created based on:

  • TLS BR Version 2.0.8
  • EVG Version 2.0.1

XolphinMartijn added a commit to XolphinMartijn/servercert that referenced this issue Oct 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
clean-up Items for future clean-up ballot
Projects
None yet
Development

No branches or pull requests

1 participant