Re: Clarifications on ETSI terminology and scheme

2018-11-02 Thread Ryan Sleevi via dev-security-policy
On Fri, Nov 2, 2018 at 1:31 PM clemens.wanko--- via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > II. Assessment and certification statements: > - ETSI requires the auditing of the past period as well as of the current > operations status: > o In chapter 7.9 of the

Re: Clarifications on ETSI terminology and scheme

2018-11-02 Thread clemens.wanko--- via dev-security-policy
Dear all, on behalf of ACAB’c we like to comment on that as follows: We would like to clarify the following normative points defined by the EA and by the ISO/IEC 17065/ETSI/eIDAS: I. Accreditation of CAB: - The eIDAS/ETSI accredited CAB in Europe are in general all accredited according

Re: Clarifications on ETSI terminology and scheme

2018-10-31 Thread Ryan Sleevi via dev-security-policy
On Wed, Oct 31, 2018 at 4:05 PM Dimitris Zacharopoulos wrote: > > For example, when we talk about expectations of CAs, we don't talk about > > what they 'could' do, we talk about what they MUST do, because at the end > > of the day, that's the bar they're being held to. It's certainly true >

Re: Clarifications on ETSI terminology and scheme

2018-10-31 Thread Dimitris Zacharopoulos via dev-security-policy
On 31/10/2018 8:00 μμ, Ryan Sleevi via dev-security-policy wrote: [...] Dimitris, I'm sorry, but I don't believe this is a correct correction. EN 319 403 incorporates ISO/IEC 17065; much like the discussion about EN 319 411-2 incorporating, but being separate from, EN 319 411-1, the

Re: Clarifications on ETSI terminology and scheme

2018-10-31 Thread Ryan Sleevi via dev-security-policy
On Wed, Oct 31, 2018 at 12:55 PM Dimitris Zacharopoulos via dev-security-policy wrote: > > > On 31/10/2018 4:47 μμ, Ryan Sleevi via dev-security-policy wrote: > > There's a lot of nitpicking in this, and I feel that if you want to > > continue this discussion, it would be better off in a