Confirmed users, Administrators
5,526
edits
m (added another sentence about CPA Canada) |
(Replaced section with text provided by ACAB'c representatives) |
||
| Line 168: | Line 168: | ||
== Verifying ETSI Auditor Qualifications == | == Verifying ETSI Auditor Qualifications == | ||
For ETSI auditors, a representative of Mozilla | For ETSI auditors, a representative of Mozilla checks to verify the qualifications of both the National Accreditation Body (NAB) and the Conformity Assessment Body (CAB) which is the auditor. | ||
* | |||
* | ==== Simplified Check ==== | ||
* | Check whether the accredited CAB is listed as ACAB’c member in https://www.acab-c.com/acab-c-members | ||
* All ACAB’c member CABs were carefully vetted that they: | |||
*# possess the required accreditation as per the Standard Check; | |||
*# have signed the [https://www.acab-c.com/terms-conditions-and-policies/ ACAB’c code of conduct]; and | |||
*# use the Audit Attestation template agreed with the Browsers via the CA/Browser Forum. | |||
==== Standard Check ==== | |||
# Require the ETSI auditor to provide as evidence links to their | |||
## National Accreditation Body (NAB) and their | |||
## accreditation documentation, listed by the NAB on their webpages. | |||
# Perform confirm the following: | |||
## The NAB is listed as “full member” under https://european-accreditation.org/ea-members/directory-of-ea-members-and-mla-signatories/ | |||
## The accreditation documentation was issued by that NAB (their webpages), | |||
## The CABs accreditation documentation explicitly refers to: | |||
### ETSI EN 319 403 as the relevant standard for the CAB to perform ETSI audits, allocated under ISO 17065 as framing standard. Option on top: The EU eIDAS Regulation 910/2014 can be listed to supplement that information but – alone – is not sufficient to demonstrate ETSI auditors qualification. plus | |||
### ETSI EN 319 401 and ETSI EN 319 411-1, as standards to audit publicly trusted CA/Trust Service Provider against and (optional on top) | |||
### ETSI EN 319 411-2, as standard to audit publicly trusted CA/Trust Service Provider against, which issue QWACS certificates according to the EU eIDAS Regulation 910/2014. | |||
==== Comprehensive Check ==== | |||
This check is only needed if the Standard Check was not successful. | |||
# Require the ETSI auditor to provide a comprehensive written explanation on why they are not conformant with the above mentioned scheme. The auditor must provide a rationale clearly referring back to | |||
## the European Accreditation to demonstrate they act under the EU accreditation scheme, | |||
## the ISO 17065 plus ETSI EN 310 403 to demonstrate they are accredited/allowed to audit publicly trusted CA/Trust Service Provider according to ETSI EN 319 401 and ETSI EN 319 411-1 and as an option on top | |||
## the ETSI EN 319 411-2for QWACS certificates according to the EU eIDAS Regulation 910/2014. | |||
# Judge the documents delivered; and | |||
# Request external review from ACAB’c to provide opinion about the CAB's accreditation. | |||