MCS要給GOOGLE的DOMAINs重做CERTIFICATES? 估計中國政府想讀某些人的GMAIL或者GOOGLEDRIVE
Mozilla followed in Google』s footsteps today:
After reviewing the circumstances and a robust discussion on our public mailing list, we have concluded that CNNIC』s behaviour in issuing an unconstrained intermediate certificate to a company with no documented PKI practices and with no oversight of how the private key was stored or controlled was an 『egregious practice』 as per Mozilla』s CA Certificate Enforcement Policy. Therefore, after public discussion and consideration of the scope and impact of a range of options, we have decided to update our code so that Mozilla products will no longer trust any certificate issued by CNNIC』s roots with a notBefore date on or after 1st April 2015.