Re: CCADB Updates August 20-24: Policy Document Objects

2020-08-26 Thread Kathleen Wilson via dev-security-policy
Here are a couple clarifications about this CCADB update. Please let me know if you run into any problems or have further questions about it. 1) The multiple-policy-documents feature is only available at the root certificate level. 2) Changes to root certificate records and their policy

Re: Verifying Auditor Qualifications

2020-08-26 Thread Kathleen Wilson via dev-security-policy
On 6/3/20 4:20 PM, Kathleen Wilson wrote: It recently came to my attention that I need to be more diligent in verifying auditor qualifications. https://wiki.mozilla.org/CA/Audit_Statements#Auditor_Qualifications All, While re-verifying auditor qualifications I have run into the following

Re: Verifying Auditor Qualifications

2020-08-26 Thread Ben Wilson via dev-security-policy
In a draft template for audit attestations, provided by the ACAB'c, the template would provide a URL to the NAB's certification of the CAB with a statement that the NAB had certified the CAB to perform "certification of trust services according to 'EN ISO/IEC 17065:2012' and 'ETSI EN 319 403

Re: Verifying Auditor Qualifications

2020-08-26 Thread Kathleen Wilson via dev-security-policy
On 8/26/20 12:35 PM, Nikolaos Soumelidis wrote: One would expect that they would put that in the accreditation documents or references, That helps answer part of my question -- that it is reasonable to expect the NAB's accreditation document to specifically list these ETSI EN standards.

RE: Verifying Auditor Qualifications

2020-08-26 Thread Nikolaos Soumelidis via dev-security-policy
>> I will greatly appreciate it if you can reach out to them again. Please let me know what information you would need. Will definitely do. Probably no other information will be needed by you, but I do appreciate the offer. >> Note that with the exception of 4 CABs accredited by Accredia and 1

Re: Verifying Auditor Qualifications

2020-08-26 Thread Kathleen Wilson via dev-security-policy
On 8/26/20 2:01 PM, Nikolaos Soumelidis wrote: I will greatly appreciate it if you can reach out to them again. Please let me know what information you would need. Will definitely do. Probably no other information will be needed by you, but I do appreciate the offer. Thanks! Please note

RE: Verifying Auditor Qualifications

2020-08-26 Thread Nikolaos Soumelidis via dev-security-policy
Dear Kathleen, As you accurately pointed out, Accredia's Regulations (Circular No.8/2017 and the updated No.5/2020) enforces the use of ETSI EN 319 403 and the related ETSI EN 319 4xx standards by all its accredited CABs since the beginning of this accreditation. The accreditation regulation

Re: Verifying Auditor Qualifications

2020-08-26 Thread Kathleen Wilson via dev-security-policy
On 8/26/20 12:29 PM, Ben Wilson wrote: This raises the question of whether NABs typically include ETSI EN 319 401, ETSI EN 319 411-1 and ETSI EN 319 411-2 in such CAB certification records. The answer to that question is yes, the other NABs typically do list that information directly in the