Confirmed users, Administrators
5,526
edits
| Line 12: | Line 12: | ||
* Transfers the private keys to another CA that does not have root certificates included in Mozilla’s program. | * Transfers the private keys to another CA that does not have root certificates included in Mozilla’s program. | ||
Whenever a root certificate's private key is | Whenever a root certificate's private key is going to be physically relocated, the CA should take the following steps, and [https://www.mozilla.org/en-US/about/governance/policies/security-group/bugs/ immediately notify Mozilla if a problem occurs]. | ||
# Make sure the annual audit statements are current, and [mailto:certificates@mozilla.org notify Mozilla of the pending change]. | # Make sure the annual audit statements are current, and [mailto:certificates@mozilla.org notify Mozilla of the pending change]. | ||
# Create a transfer plan (and legal agreement if more than one CA is involved) and have it reviewed by the auditors. | # Create a transfer plan (and legal agreement if more than one CA is involved) and have it reviewed by the auditors. | ||