Re: ETSI auditors still not performing full annual audits?

2017-07-05 Thread cornelia.enke66--- via dev-security-policy
Am Montag, 19. Juni 2017 21:15:09 UTC+2 schrieb Kathleen Wilson: > I just filed https://bugzilla.mozilla.org/show_bug.cgi?id=1374381 about an > audit statement that I received for SwissSign. I have copied the bug > description below, because I am concerned that there still may be ETSI >

Re: ETSI auditors still not performing full annual audits?

2017-06-20 Thread Ryan Sleevi via dev-security-policy
Thanks, Kathleen, for raising these issues. At a high level, this highlights an interesting concern. If we, as the broader community, lack the expertise to appropriate review and consume the audit reports as intended, it may signal a question about whether or not we should consider consuming ETSI

Re: ETSI auditors still not performing full annual audits?

2017-06-19 Thread Kathleen Wilson via dev-security-policy
On Monday, June 19, 2017 at 12:21:46 PM UTC-7, Peter Bowen wrote: > It seems there is some confusion. The document presented would appear > to be a Verified Accountant Letter (as defined in the EV Guidelines) > and can used as part of the process to validate a request for an EV > certificate. It

Re: ETSI auditors still not performing full annual audits?

2017-06-19 Thread Peter Bowen via dev-security-policy
On Mon, Jun 19, 2017 at 12:14 PM, Kathleen Wilson via dev-security-policy wrote: > I just filed https://bugzilla.mozilla.org/show_bug.cgi?id=1374381 about an > audit statement that I received for SwissSign. I have copied the bug > description below,