Re: Verifying Auditor Qualifications

2020-07-13 Thread clemens.wanko--- via dev-security-policy
Hi Ryan, thanks for your post. And certainly yes: it’s our first goal to serve the needs of our actual consumers. The browsers belong to those in the front row. We are aware of that as we are aware that there is space for improvement for the council. With regard to your statement to our webpage

Re: Verifying Auditor Qualifications

2020-07-03 Thread clemens.wanko--- via dev-security-policy
All, on behalf of the Accredited Conformity Assessment Bodies council we would like to provide the following background information to the guideline “Verifying ETSI Auditor Qualification” as stated here: https://wiki.mozilla.org/CA/Audit_Statements#Verifying_ETSI_Auditor_Qualifications The guid

Re: Auditing of CA facilities in lockdown because of an environmental disaster/pandemic

2020-03-12 Thread clemens.wanko--- via dev-security-policy
Situation from ACAB'c ETSI auditors point of view: On one hand it is quite simple: if the auditor cannot perform the audit as foreseen in the certification program no certificate can be issued. In case a surveillance audit cannot be performed, the certification body must withdraw the affected c

Re: Auditor letters and incident reports

2019-08-23 Thread clemens.wanko--- via dev-security-policy
Dear all, just a short note on that with regard to auditing and Audit Attestations based upon ETSI: throughout the audit we check the incidents of the current audit period as documented by the CA (have they been addressed at a sufficient level, have the measures taken proven that they are suffi

Re: Clarifications on ETSI terminology and scheme

2018-11-02 Thread clemens.wanko--- via dev-security-policy
Dear all, on behalf of ACAB’c we like to comment on that as follows: We would like to clarify the following normative points defined by the EA and by the ISO/IEC 17065/ETSI/eIDAS: I. Accreditation of CAB: - The eIDAS/ETSI accredited CAB in Europe are in general all accredited according IS

Re: Misissuance and BR Audit Statements

2018-08-16 Thread clemens.wanko--- via dev-security-policy
Dear all, this is a joint response from ETSI ESI and ACABc: ETSI have published a supplement to its audit requirements specifically to address specific requirements of Mozilla, and other CA/Browser Forum members, for auditing Trust Service Providers that issue Publicly-Trusted Certificates TS 1