mozilla / www.ccadb.org

Website about the Mozilla-run Common CA Database
9 stars 12 forks source link

Add note to ccadb.org/cas/updates that CAs direclty update intermediate cert audit info #4

Closed WilsonKathleen closed 7 years ago

WilsonKathleen commented 7 years ago

There has been confusion about the Audit Case process in regards to intermediate cert records. CAs keep wondering how to indicate which intermediate certs the Audit statements also apply to. So we need to update ccadb.org/cas/updates to clarify that the Audit Case process is only for the certificates that are directly included in the root stores, and that CAs must directly update the audit statements for their intermediate cert records.

Here's a possible way to handle this...

Update the first paragraph of ccadb.org/cas/updates to say: All CAs are required to update the audit, CP, CPS and test website information for their certificate hierarchies at least annually. CAs are expected to maintain their intermediate certificate records <link to ccadb.org/cas/intermediates> themselves and to directly enter the corresponding updated audit statements <link to ccadb.org/cas/fields#audit-information>. This page describes the process for providing annual updates for the root certificates that are directly included in Root Stores.