CA/Communications: Difference between revisions

m
Line 197: Line 197:
2) Implement automated checks to signal a red flag for domains such as .int and null characters in the Common Name and subjectAlternativeName of certificates.
2) Implement automated checks to signal a red flag for domains such as .int and null characters in the Common Name and subjectAlternativeName of certificates.
3) Maintain your own list of ICANN approved TLDs that are eligible to be used for domains in certificates issued within your CA hierarchy. If a new TLD is created by IANA, make an explicit decision whether or not to add the new TLD to your list.
3) Maintain your own list of ICANN approved TLDs that are eligible to be used for domains in certificates issued within your CA hierarchy. If a new TLD is created by IANA, make an explicit decision whether or not to add the new TLD to your list.
(http://www.icann.org/en/registries/top-level-domains.htm)
http://www.icann.org/en/registries/top-level-domains.htm


Mozilla strongly encourages you to take prompt action in order to ensure the continued security and trust-ability of your CA service.  
Mozilla strongly encourages you to take prompt action in order to ensure the continued security and trust-ability of your CA service.  


Kathleen Wilson
Kathleen Wilson
Confirmed users, Administrators
5,526

edits