Add Lithuanian National Root Certificates
Categories
(CA Program :: CA Certificate Root Program, task, P2)
Tracking
(Not tracked)
People
(Reporter: md, Assigned: kathleen.a.wilson)
Details
(Whiteboard: [ca-verifying] - Need BR Self Assessment, full audit history, updated CP/CPS)
Attachments
(9 files, 5 obsolete files)
|
111.00 KB,
application/msword
|
Details | |
|
30.77 KB,
application/pdf
|
Details | |
|
28.15 KB,
application/vnd.oasis.opendocument.text
|
Details | |
|
6.44 KB,
text/plain
|
Details | |
|
27.38 KB,
application/vnd.oasis.opendocument.text
|
Details | |
|
537.97 KB,
application/pdf
|
Details | |
|
273.55 KB,
application/pdf
|
Details | |
|
2.12 MB,
application/pdf
|
Details | |
|
101.00 KB,
application/pdf
|
Details |
Comment 1•18 years ago
|
||
Updated•18 years ago
|
Updated•18 years ago
|
Comment 2•18 years ago
|
||
Comment 8•18 years ago
|
||
Comment 10•18 years ago
|
||
| Reporter | ||
Comment 11•18 years ago
|
||
Comment 12•18 years ago
|
||
| Reporter | ||
Comment 13•18 years ago
|
||
Comment 14•17 years ago
|
||
| Reporter | ||
Comment 15•17 years ago
|
||
| Reporter | ||
Comment 16•17 years ago
|
||
| Reporter | ||
Comment 17•17 years ago
|
||
Updated•17 years ago
|
Comment 18•17 years ago
|
||
| Assignee | ||
Comment 19•17 years ago
|
||
| Reporter | ||
Comment 20•17 years ago
|
||
| Reporter | ||
Comment 21•17 years ago
|
||
| Assignee | ||
Comment 22•17 years ago
|
||
| Reporter | ||
Comment 23•17 years ago
|
||
| Assignee | ||
Comment 24•17 years ago
|
||
| Assignee | ||
Comment 25•17 years ago
|
||
| Reporter | ||
Comment 26•17 years ago
|
||
| Assignee | ||
Comment 27•17 years ago
|
||
| Reporter | ||
Comment 28•17 years ago
|
||
| Assignee | ||
Comment 29•16 years ago
|
||
| Reporter | ||
Comment 30•16 years ago
|
||
| Assignee | ||
Comment 31•16 years ago
|
||
Comment 32•16 years ago
|
||
| Assignee | ||
Comment 33•16 years ago
|
||
| Assignee | ||
Updated•16 years ago
|
| Assignee | ||
Comment 34•16 years ago
|
||
| Assignee | ||
Updated•16 years ago
|
| Assignee | ||
Comment 35•12 years ago
|
||
| Reporter | ||
Comment 36•12 years ago
|
||
| Assignee | ||
Updated•12 years ago
|
| Reporter | ||
Comment 37•11 years ago
|
||
| Assignee | ||
Comment 38•11 years ago
|
||
| Reporter | ||
Comment 39•11 years ago
|
||
| Reporter | ||
Comment 40•11 years ago
|
||
| Reporter | ||
Comment 41•11 years ago
|
||
| Assignee | ||
Comment 42•11 years ago
|
||
| Reporter | ||
Comment 43•11 years ago
|
||
| Reporter | ||
Comment 44•11 years ago
|
||
| Reporter | ||
Comment 45•11 years ago
|
||
| Assignee | ||
Comment 46•10 years ago
|
||
| Reporter | ||
Comment 47•10 years ago
|
||
| Assignee | ||
Comment 48•10 years ago
|
||
| Reporter | ||
Comment 49•10 years ago
|
||
| Assignee | ||
Comment 50•10 years ago
|
||
| Reporter | ||
Comment 51•10 years ago
|
||
| Assignee | ||
Comment 52•10 years ago
|
||
| Reporter | ||
Comment 53•10 years ago
|
||
| Reporter | ||
Comment 54•10 years ago
|
||
| Assignee | ||
Comment 55•10 years ago
|
||
| Reporter | ||
Comment 56•10 years ago
|
||
| Assignee | ||
Comment 57•10 years ago
|
||
| Reporter | ||
Comment 58•10 years ago
|
||
| Assignee | ||
Comment 59•10 years ago
|
||
| Reporter | ||
Comment 60•10 years ago
|
||
| Assignee | ||
Comment 61•10 years ago
|
||
| Assignee | ||
Comment 62•10 years ago
|
||
| Assignee | ||
Comment 63•10 years ago
|
||
| Reporter | ||
Comment 64•10 years ago
|
||
| Assignee | ||
Comment 65•10 years ago
|
||
| Assignee | ||
Updated•9 years ago
|
| Reporter | ||
Comment 66•9 years ago
|
||
Updated•8 years ago
|
| Reporter | ||
Comment 67•6 years ago
|
||
| Reporter | ||
Comment 68•6 years ago
|
||
Comment 69•6 years ago
|
||
Moudrick: the attestation letter in comment 67 does not meet Mozilla requirements because it is dated before the end of the audit period. Mozilla policy section 3.1.4(9) states "the date the report was issued (which will necessarily be after the end date or point-in-time date); "
| Reporter | ||
Comment 70•6 years ago
|
||
Thanks, Wayne. Trying to fix this but still confused a bit. Here is how our dates looks like:
Standard Audit Statement Date : 6/9/2018
Standard Audit Period Start Date: 5/9/2018
Standard Audit Period End Date: 5/21/2018
The Audit Statement date is after the Audit time frame (5/9/2018 to 5/21/2018)..
Comment 71•6 years ago
|
||
Moudrick: Are you stating that only 12 days were audited? I can't seem to find reference to May 9 in Comment #67, nor June 9. Instead, the statement is dated 2019-02-08.
It sounds like there is confusion about what an audit period is. The CA/Browser Forum has extensively discussed this, in order to try and ensure there is no ambiguity. Ballot 196 introduced this definition into the Baseline Requirements, after gaining feedback from both WebTrust and ETSI, and states that:
Audit Period: In a period-of-time audit, the period between the first day (start) and the last day of
operations (end) covered by the auditors in their engagement. (This is not the same as the period of time
when the auditors are on-site at the CA.) The coverage rules and maximum length of audit periods are defined
in section 8.1.
For example, WebTrust "forbids" (by virtue of the professional engagement standards such as AICPA's AT-C) audit periods of less than two months, without significantly raising concerns about the audit itself, so if it were possible to obtain an ETSI audit for 12 days, that would be concerning.
It sounds as if you're instead interpreting "audit period" to mean the time that the auditors were on-site - an interpretation the Baseline Requirements explicitly calls out as an incorrect understanding.
The Audit Attestation Letter in Comment #67 states:
"It took place from May 21st 2018 until May 22nd 2018 as well as on November 19th, 2018, and covered the period from May 21st 2018 until May 20th 2019."
Please re-review the letter attached in Comment #67. I'm concerned that these dates are not reflected in the paperwork presently provided.
| Reporter | ||
Comment 72•6 years ago
|
||
Thanks, Ryan. You are right, I misunderstood the audit period.
The dates shown above (5/9/2018 - 5/21/2018) are the timeframe when the audit took place but not the assessment period (which in our case is 1 year).
Our Audit Attestation Letter was issued just a few days ago (because of contractual misunderstandings not related to the audit statement). I'll recheck the dates and then update the case info.
| Assignee | ||
Comment 73•6 years ago
|
||
This request will need to go back through the "Information Verification" phase after the CA has provided the following:
-
BR Self Assessment: https://wiki.mozilla.org/CA/BR_Self-Assessment
-
Full audit history for the roots to be included
-
Current audit statements that meet Mozilla's policy requirements
https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy#313-audit-parameters
https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy#314-public-audit-information -
Current CP/CPS documents
| Assignee | ||
Comment 74•6 years ago
|
||
Closing this request per Comment #73, and because these roots have valid from 2013 so it is very likely that these CA hierarchies cannot meet all of our current requirements.
If the CA chooses to create a new root certificate, they may start a new root inclusion request as described here:
https://wiki.mozilla.org/CA/Application_Instructions#Create_Root_Inclusion.2FUpdate_Request
Updated•3 years ago
|
Description
•