Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Require CAs to use the CAB Forum EV Policy OID #160

Closed
wthayer opened this issue Nov 13, 2018 · 4 comments
Closed

Require CAs to use the CAB Forum EV Policy OID #160

wthayer opened this issue Nov 13, 2018 · 4 comments
Labels
2.8 Mozilla Root Store Policy v. 2.8

Comments

@wthayer
Copy link
Contributor

wthayer commented Nov 13, 2018

Consider requiring CAs to use the CAB Forum EV Policy OID rather than their own custom EV OID. This is already a strong SHOULD, but there are legacy issues to consider.

Discussion: https://groups.google.com/d/msg/mozilla.dev.security.policy/38fR-fiYJt0/1qnHTm8MAwAJ

EV Processing in Firefox: https://wiki.mozilla.org/CA/EV_Processing_for_CAs

@BenWilson-Mozilla BenWilson-Mozilla added the 2.8 Mozilla Root Store Policy v. 2.8 label Dec 29, 2020
@timfromdigicert
Copy link

There are also technical issues to consider, because certificates have to work in all browsers. Not all browsers treat all policy OID positions as equal (despite the fact that the RFCs don't consider order as relevant), and not all browsers recognize the CABF EV OIDs for all CAs.

@sleevi
Copy link
Contributor

sleevi commented Apr 7, 2021

Note: this is being tackled in sleevi/cabforum-docs#36 for the CABF, to resolve both the requirement and the positioning, to help implementations align on interoperable behavior.

@BenWilson-Mozilla
Copy link
Collaborator

Section 7.1.6.4 of the Baseline Requirements states, "Effective 2020‐09‐30, a Certificate issued to a Subscriber MUST contain, within the Certificate’s certificatePolicies extension, one or more policy identifier(s) that are specified beneath the CA/Browser Forum’s reserved policy OID arc of {joint-iso-itu-t(2) international-organizations(23)ca-browser-forum(140) certificate-policies(1)} (2.23.140.1). ...
Certificate Policy Identifier: 2.23.140.1.1
If the Certificate complies with these Requirements and has been issued and operated in accordance with the CA/Browser Forum Guidelines for the Issuance and Management of Extended Validation Certificates (“EV Guidelines”)."

So, can this issue be closed? (Eventually, in the long run, Mozilla would then cease supporting CA-specific EV OIDs.)

@BenWilson-Mozilla
Copy link
Collaborator

Closing issue as resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2.8 Mozilla Root Store Policy v. 2.8
Projects
None yet
Development

No branches or pull requests

4 participants