Re: ETSI audits not listing audit periods

2017-11-07 Thread Jakob Bohm via dev-security-policy
On 06/11/2017 17:05, m.wiedenho...@tuvit.de wrote: TÜViT as a conformity assessment body would like to add some explanations to clear up some misunderstandings about ETSI auditing. First of all, we would like to give one preliminary remark. ETSI has separated the TSP technical requirements

Re: ETSI audits not listing audit periods

2017-11-07 Thread Moudrick M. Dadashov via dev-security-policy
Thank you for clarification. Do you think the terms "/approval scheme/", "/supervision scheme/", "/accreditation//scheme/" etc. (used in some ETSI TSs or the Commission Decisions) have the same meaning and ETSI EN 319 403 is just one of possible "/certification scheme/s"? Thanks, M.D. On

Re: ETSI audits not listing audit periods

2017-11-07 Thread m.wiedenhorst--- via dev-security-policy
TÜViT as a conformity assessment body would like to add some explanations to clear up some misunderstandings about ETSI auditing. First of all, we would like to give one preliminary remark. ETSI has separated the TSP technical requirements (ETSI EN 319 411-1, ETSI EN 319 401) from the CAB

Re: ETSI audits not listing audit periods

2017-11-01 Thread Arno Fiedler via dev-security-policy
Am Montag, 30. Oktober 2017 22:19:31 UTC+1 schrieb Ryan Sleevi: > On Mon, Oct 30, 2017 at 3:50 PM, Kathleen Wilson via dev-security-policy < > dev-security-policy@lists.mozilla.org> wrote: > > > > How do we get all auditors to start meeting our audit statement > > requirements? > > > > Why haven't

Re: ETSI audits not listing audit periods

2017-10-31 Thread Gervase Markham via dev-security-policy
Hi Arno, On 31/10/17 08:46, Arno Fiedler wrote: > there is a problem with the auditor qualification and the national > accreditation of some auditing bodies. Can you help us understand what about the discussion so far leads you to that conclusion? It seems to me that the problem being raised is

Re: ETSI audits not listing audit periods

2017-10-31 Thread Arno Fiedler via dev-security-policy
Hello Kathleen, there is a problem with the auditor qualification and the national accreditation of some auditing bodies. We´ll ask ACABc to suggest a solution to take care about proper education of "qualified" auditors and "good practise" audit statements as suggested by Mozilla, maybe we

Re: ETSI audits not listing audit periods

2017-10-30 Thread Kathleen Wilson via dev-security-policy
On Monday, October 30, 2017 at 5:02:08 PM UTC-7, Buschart, Rufus wrote: > Our ETSI audit report > (https://www.siemens.com/corp/pool/pki/siemens_etsi.pdf) states: > > > An audit of the certification service, documented in a report, provided > > evidence that the requirements of the following >

RE: ETSI audits not listing audit periods

2017-10-30 Thread Buschart, Rufus via dev-security-policy
o: mozilla-dev-security-pol...@lists.mozilla.org Subject: Re: ETSI audits not listing audit periods On Monday, October 30, 2017 at 2:59:31 PM UTC-7, Ryan Sleevi wrote: > > I would expect that it would be incumbent on the CABs and the CAs > providing EN 319 411-1 certificates to help the comm

Re: ETSI audits not listing audit periods

2017-10-30 Thread Kathleen Wilson via dev-security-policy
On Monday, October 30, 2017 at 2:59:31 PM UTC-7, Ryan Sleevi wrote: > > I would expect that it would be incumbent on the CABs and the CAs providing > EN 319 411-1 certificates to help the community better understand the level > of assurance provided. That is, I think those supporting the

Re: ETSI audits not listing audit periods

2017-10-30 Thread Ryan Sleevi via dev-security-policy
On Mon, Oct 30, 2017 at 3:50 PM, Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > > How do we get all auditors to start meeting our audit statement > requirements? > > Why haven't all included CAs communicated these requirements to their > auditors? > > Why