CA/Audit Statements: Difference between revisions

Jump to navigation Jump to search
Replaced section with text provided by ACAB'c representatives
m (added another sentence about CPA Canada)
(Replaced section with text provided by ACAB'c representatives)
Line 168: Line 168:


== Verifying ETSI Auditor Qualifications ==
== Verifying ETSI Auditor Qualifications ==
For ETSI auditors, a representative of Mozilla performs the following steps to verify the qualifications of both the auditor which is the Conformity Assessment Body (CAB), and the National Accreditation Body (NAB).
For ETSI auditors, a representative of Mozilla checks to verify the qualifications of both the National Accreditation Body (NAB) and the Conformity Assessment Body (CAB) which is the auditor.
* Find the name and location of the NAB
 
** There is a voluntary, informative (and potentially out-of-date) list here: https://ec.europa.eu/futurium/en/content/list-conformity-assessment-bodies-cabs-accredited-against-requirements-eidas-regulation
==== Simplified Check ====
** The CAB should indicate the NAB and their Certificate. Confirm the Certificate with the NAB (of which they're all required to have online search capabilities, per the ISO/IEC standards the NABs themselves implement), and then look for either ETSI or ISO 17065.
Check whether the accredited CAB is listed as ACAB’c member in https://www.acab-c.com/acab-c-members
* Make sure the NAB is listed at European Accreditation via https://european-accreditation.org/
* All ACAB’c member CABs were carefully vetted that they:
** Check that the scope of the NAB includes ???
*# possess the required accreditation as per the Standard Check;
* Within the NAB, perform a search for the CAB (taking care to make sure the addresses match)
*# have signed the [https://www.acab-c.com/terms-conditions-and-policies/ ACAB’c code of conduct]; and
* The CAB either needs to be assessed against ISO 17065 (per EN 319 403) or against the ETSI standards themselves (for those NABs that do so)
*# use the Audit Attestation template agreed with the Browsers via the CA/Browser Forum.
** Notably: QWACs are allowed to be issued based on standards other than ETSI, so if the CAB asserts that they're assessed against (national scheme), that's not necessarily sufficient to prove they meet the BRs or the Mozilla Policy. An example of this might be tScheme or the GOV.UK ID Scheme, the former which is not qualified and the latter which is a "notified scheme" (aka QWAC issuer), but neither of these use the ETSI guidelines and so neither meet the BRs / Mozilla Policy, and are more akin to "Government equivalent audits"
 
** Also note that the NAB an auditor is assessed against MAY NOT be the NAB in which they're headquartered, depending on complexities around the mutual recognition treaties
==== Standard Check ====
# Require the ETSI auditor to provide as evidence links to their
## National Accreditation Body (NAB) and their
## accreditation documentation, listed by the NAB on their webpages.
# Perform confirm the following:
## The NAB is listed as “full member” under https://european-accreditation.org/ea-members/directory-of-ea-members-and-mla-signatories/
## The accreditation documentation was issued by that NAB (their webpages),
## The CABs accreditation documentation explicitly refers to:
### ETSI EN 319 403 as the relevant standard for the CAB to perform ETSI audits, allocated under ISO 17065 as framing standard. Option on top: The EU eIDAS Regulation 910/2014 can be listed to supplement that information but – alone – is not sufficient to demonstrate ETSI auditors qualification. plus
### ETSI EN 319 401 and ETSI EN 319 411-1, as standards to audit publicly trusted CA/Trust Service Provider against and (optional on top)
### ETSI EN 319 411-2, as standard to audit publicly trusted CA/Trust Service Provider against, which issue QWACS certificates according to the EU eIDAS Regulation 910/2014.
 
==== Comprehensive Check ====
This check is only needed if the Standard Check was not successful.
# Require the ETSI auditor to provide a comprehensive written explanation on why they are not conformant with the above mentioned scheme. The auditor must provide a rationale clearly referring back to
## the European Accreditation to demonstrate they act under the EU accreditation scheme,
## the ISO 17065 plus ETSI EN 310 403 to demonstrate they are accredited/allowed to audit publicly trusted CA/Trust Service Provider according to ETSI EN 319 401 and ETSI EN 319 411-1 and as an option on top
## the ETSI EN 319 411-2for QWACS certificates according to the EU eIDAS Regulation 910/2014.
# Judge the documents delivered; and
# Request external review from ACAB’c to provide opinion about the CAB's accreditation.
Confirmed users, Administrators
5,526

edits

Navigation menu