Confirmed users, Administrators
5,526
edits
m (→October 2010) |
|||
Line 197: | Line 197: | ||
2) Implement automated checks to signal a red flag for domains such as .int and null characters in the Common Name and subjectAlternativeName of certificates. | 2) Implement automated checks to signal a red flag for domains such as .int and null characters in the Common Name and subjectAlternativeName of certificates. | ||
3) Maintain your own list of ICANN approved TLDs that are eligible to be used for domains in certificates issued within your CA hierarchy. If a new TLD is created by IANA, make an explicit decision whether or not to add the new TLD to your list. | 3) Maintain your own list of ICANN approved TLDs that are eligible to be used for domains in certificates issued within your CA hierarchy. If a new TLD is created by IANA, make an explicit decision whether or not to add the new TLD to your list. | ||
http://www.icann.org/en/registries/top-level-domains.htm | |||
Mozilla strongly encourages you to take prompt action in order to ensure the continued security and trust-ability of your CA service. | Mozilla strongly encourages you to take prompt action in order to ensure the continued security and trust-ability of your CA service. | ||
Kathleen Wilson | Kathleen Wilson |