mozilla / www.ccadb.org

Website about the Mozilla-run Common CA Database
10 stars 13 forks source link

Update http://ccadb.org/cas/fields#audit-information #6

Closed WilsonKathleen closed 7 years ago

WilsonKathleen commented 7 years ago

The second row of http://ccadb.org/cas/fields#audit-information needs to be updated. Probably best to change it to: URL to an auditor's statement that the operation of this certificate has been audited according to Mozilla's Root Store Policy <link: https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy#audit-criteria>.

Also, please add a row for Audit Period, with text: For each Audit Statement provide the Audit Period Start Date and Audit Period End Date. In a period‐of‐time audit, the Audit Period is the period between the first day (start) and the last day of operations (end) covered by the auditors in their engagement. The period during which the CA issues Certificates SHALL be divided into an unbroken sequence of audit periods. An audit period MUST NOT exceed one year in duration.

gerv commented 7 years ago

@WilsonKathleen: using the text you propose would be putting something Mozilla-specific into a generic CCADB document. Is that what you want? Might it not be better just to update the criteria version numbers?

WilsonKathleen commented 7 years ago

Oh yes, you are correct, so please add ETSI EN 319 411-1 v1.1.1 and ETSI EN 319 411-2 v2.1.1 to the second row (the 'Standard Audit' row).