Changes

Jump to: navigation, search

CA/Required or Recommended Practices

8,582 bytes removed, 15:56, 30 March 2022
CP/CPS Documents will be Reviewed!: Moved content to CA/CPS_Review
your CP/CPS documentation will be thoroughly reviewed and commented on. Concerns raised by the reviewer must be sufficiently resolved before the request will be allowed to enter [[CA/Application_Verification#Public_discussion|public discussion]].
Here are previous reviews of CP/CPS documents:* [https://bugzilla.mozilla.org/show_bug.cgi?id=1313982#c41 Review of SECOM's CPs and CPSes] * [https://bugzilla.mozilla.org/show_bug.cgi?id=1628720#c16 BR and EV Review on eTugra's CPS] [https://bugzilla.mozilla.org/attachment.cgi?id=9254979 (Download full review in XLS attachment)]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1706228#c9 BR and EV Review on DigiCert's CP/CPS] [https://bugzilla.mozilla.org/attachment.cgi?id=9252944 (Download full review in XLS attachment)]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1679258#c9 BR and EV Review on D-TRUST's CP/CPS] [https://bugzilla.mozilla.org/attachment.cgi?id=9243128 (Download full review in XLS attachment)]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1554846#c50 Detailed Extended Validation Review Feedback to iTrusChina on EV aspects of CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1454977#c75 Second Review on ACIN - Global Trusted Sign's CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1664161#c6 Detailed BR Review Feedback to Telia on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1705904#c20 BR Review of KIR's CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1454977#c52 Detailed BR and EV Review Feedback to ACIN - Global Trusted Sign]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1102143#c38 Detailed BR and EV Review Feedback on Firmaprofesional's CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1563417#c19 Detailed BR and EV Review Feedback on Chunghwa Telecom's CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1695487#c6 Detailed BR Review Feedback to HARICA on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1701317#c6 Detailed Review Feedback to ISRG/Let's Encrypt on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1690054#c8 Detailed Extended Validation Review Feedback to HARICA on EV aspects of CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1493679#c25 Detailed BR and EV Review Feedback to Network Solutions on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1627552#c13 Detailed BR and EV Review Feedback to GLOBALTRUST2020 on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1647181#c7 Detailed BR and EV Review Feedback to Beijing CA on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1579454#c9 Detailed Extended Validation Review Feedback to NetLock on EV aspects of CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1587779#c12 Detailed Review Feedback to TunTrust on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1585951#c36 Detailed Review Feedback to ANF on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1558450#c17 Detailed Review Feedback to Digidentity on CP/CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1554846#c30 Detailed Review Feedback to iTrusChina on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1404221#c29 Detailed Review Feedback to NAVER Group on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1563417#c7 Detailed Review Feedback to Chunghwa Telecom on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1532426#c31 Initial Review Feedback to SSLCOM Group on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1551703#c6 Detailed Review Feedback to Identrust on CPS]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1528369#c10 Detailed Review Feedback to SecureTrust]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1479040#c42 Detailed Review Feedback to Certisign]* [https://groups.google.com/d/msg/mozilla.dev.security.policy/jRKOr4nvOfY/QrhdAWq_AAAJ Detailed Review Feedback on Microsec]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1102143#c25 Detailed Review Feedback on Firmaprofesional]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1403453#c13 Detailed Review Feedback on certSIGN CA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1474556#c16 Detailed Review Feedback on Dubai Government CA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1448093#c56 Detailed Review Feedback on Microsoft CA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1480510#c10 Detailed Review Feedback on Entrust CA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1464306#c29 Detailed Review Feedback on Hongkong Post CA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1442337#c37 Detailed Review Feedback on eMudhra CA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1309797#c72 Detailed Review feedback on SHECA]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1325532#c41 Detailed Review Feedback on Google Trust Services]* [https://bugzilla.mozilla.org/show_bug.cgi?id=1390803#c14 Detailed Review Feedback on GlobalSign]* [https://groups.google.com/d/msg/mozilla.dev.security.policy/36t-jbTQnTY/nwkFyzobAgAJ Review Feedback on WISeKey]** That was after [https://bugzilla.mozilla.org/show_bug.cgi?id=1403591#c17 blocking problems with the CP/CPS] were resolved.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/skev4gp_bY4/snIuP2JLAgAJ Review Feedback on Camerfirma]** CA may submit new root inclusion request for newly generated root that is fully compliant with Mozilla's Root Store Policy and the BRs.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/R2uG3wisU7s/ie_v7RHMBwAJ Review Feedback on TrustCor]** CP and CPS documents clear, well written, and they provided sufficient detail to assess the policies in place. * Review Feedback on Kamu SM (Government CPS_Review | Previous reviews of Turkey)** [https://groups.google.com/d/msg/mozilla.dev.security.policy/EtJpw8r7uGs/NmOfjdKIAwAJ CPS document clear and well written]** [https://groups.google.com/d/msg/mozilla.dev.security.policy/vjXyml8Hy-E/bhxftrNkEAAJ New requirements for Domain Validation] -- all CAs must update their CP/CPS according to section 3.2.2.4 of [https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.4.1.pdf version 1.4.1 of the BRs].* Review Feedback on Guangdong Certificate Authority (GDCA)** [https://groups.google.com/d/msg/mozilla.dev.security.policy/kB2JrygK7Vk/YVOKPfnSAQAJ English translations of documents MUST match the original document.]** [https://groups.google.com/d/msg/mozilla.dev.security.policy/kB2JrygK7Vk/blMVMaHlAwAJ CA is responsible for providing accurate translation.]* [https://groups.google.com/d/msg/mozilla.dev.security.policy/zZ5RHXCkpGM/dvx0DjswBgAJ Review Feedback on Amazon Trust Services' CP/CPS]** Amazon was commended for the clarity of their CP and CPS.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/Mezqdljjerc/eHC0JDQwBgAJ Review Feedback on Japan GPKI's CP/CPS]** Japan GPKI's CP/CPS did not contain sufficient detail, so discussion put on hold pending updated CP/CPS.* A-Trust discussion [https://groups.google.com/d/msg/mozilla.dev.security.policy/Q1beEDFdzxg/6ZILykF0AgAJ put on hold pending translation of CP/CPS into English].* [https://groups.google.com/d/msg/mozilla.dev.security.policy/uTBDhqO_IB0/bGWV7_lwBAAJ Review Feedback on ComSign's CP/CPS]** ComSign's discussion was put on hold until the CP/CPS is updated to conform to either RFC 2527 or RFC 3647, as required by the Baseline Requirements. And be translated into English.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/W0st0yN9bTM/14_-nZ7jGAAJ Review Feedback on SSC's CP/CPS]** SSC's discussion was put on hold pending updated CP/CPS.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/gKCqWRmBQ_8/A1eI_zsoAAAJ Review Feedback on ISRG's CP/CPS]** ISRG's CP/CPS had enough detail, and there were only minor corrections/clarifications to be made.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/z1rc7vUSlb0/wJkwv5x3AgAJ Review Feedback on DocuSign's CP/CPS]** DocuSign's CP/CPS had enough detail, and there were only minor corrections/clarifications to be made.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/dYoQcI0e1qA/ucp1cHfVAAAJ Review Feedback on HARICA's CP/CPS]** HARICA's CP/CPS had enough detail, and there were only minor corrections/clarifications to be made.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/47Jz7f8E4RI/ACHCpG2KCpYJ Review Feedback on LuxTrust's CP/CPS]** The concerns raised regarding LuxTrust's CP/CPS resulted in the inclusion request being put on hold until the CP/CPS was updated.* [https://groups.google.com/d/msg/mozilla.dev.security.policy/aTN3lkAt0HM/Xvmolz36PsEJ Review Feedback on Krajowa Izba Rozliczeniowa (KIR) CP/CPS]** KIR updated their CP/CPS according to the [https://groups.google.com/d/msg/mozilla.dev.security.policy/aNbK4zw_Zb8/wmwnbVbLb8cJ review feedback provided in their first discussion] ** Then had to update their CP/CPS again due to feedback in their second discussion.
=== Audit Criteria ===
Confirm
344
edits

Navigation menu