Hi Peter,

EV requirements are actually dictated by a separate set of guidelines:
https://cabforum.org/extended-validation/

They do go into detail about how to verify applicant information. It covers
how you verify the company is legally established, where its physically
operating, etc. As you can imagine, its quite detailed. Here is a short
excerpt to give you an idea of the wording.

From Section 11.4.1:

"... the CA MUST confirm that the Applicant's address, as listed in the EV
Certificate Request, is a valid business address for the Applicant or a
Parent/Subsidiary Company by reference to such QGIS, QIIS, or QTIS, and MAY
rely on the Applicant's representation that such address is its Place of
Business:"

(QGIS, QIIS, and QTIS are acronyms for different types of authoritative
sources, which the document also defines and details acceptable criteria
for)

-Vince



On Wed, Apr 19, 2017 at 6:41 PM, Peter Gutmann via dev-security-policy <
[email protected]> wrote:

> Kurt Roeckx via dev-security-policy <[email protected]>
> writes:
>
> >Both the localityName and stateOrProvinceName are Almere, while the
> province
> >is Flevoland.
>
> How much checking is a CA expected to do here?  I know that OV and DV certs
> are just "someone at this site responded to email" or whatever, but for an
> EV cert how much further does the CA actually have to go?  When e-Szignó
> Hitelesítés-Szolgáltató in Hungary certifies Autolac Car Services, Av Los
> Frutales 487 urb., Lima, Peru, are they expected to verify that it's really
> in Av Los Frutales and not Los Tolladores, or do they just go ahead and
> issue the cert?  Can someone point to the bit of the BR that says that this
> is obviously right or wrong?
>
> Peter.
> _______________________________________________
> dev-security-policy mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security-policy
>



-- 
Vincent Lynch
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to