Perhaps some explicit statements about sub-CAs would be helpful - detailing 
where responsibility lies and how a CA is required to deal with a sub-CA who is 
found to have misissued.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to