Closed
Bug 1463597
Opened 8 years ago
Closed 7 years ago
Camerfirma: Acquisition by InfoCert
Categories
(CA Program :: CA Certificate Root Program, task)
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: wthayer, Assigned: martin_ja)
Details
(Whiteboard: [ca-compliance] - Next Update - 01-October 2018)
This bug is intended to track approval of the InfoCert acquisition of Camerfirma as required by section 8.1 of the Mozilla root store policy.
News of the acquisition was first published on May 4th, 2018.
Camerfirma notified Mozilla on May 17th, 2018.
Camerfirma estimates that the transaction will close in mid-late June. Camerfirma states that they cannot answer questions about the acquisition before it closes.
I will appreciate InfoCert's answers to the following questions as soon as possible:
* Can you confirm that AC Camerfirma's entire CA operation has been acquired? This means that all of the roots, systems, policies, people, and infrastructure are not changing.
* Have any CP/CPS changes occurred, or do you expect any changes to occur as the result of this transaction? If yes, please describe them.
* Are you undergoing any additional audits, or do you expect any changes in the status of your audits or compliance certificates as the result of this transaction?
* Please describe the management changes that will result from this transaction.
* Please describe any changes to personnel that will result from this transaction.
* Please describe any changes to policies that will result from this transaction.
* Please describe any changes to systems that will happen as a result of this transaction.
* Please describe any other changes that will result from this transaction.
* Why was Mozilla not notified of this transaction 2 weeks ago when it was announced?
Please post your responses here and to the mozilla.dev.security.policy thread that I have started on this topic.
| Assignee | ||
Comment 1•8 years ago
|
||
I've been authorized by Infocert to give these answers:
* Can you confirm that the entire CA operation has been acquired? This means that all of the roots, systems, policies, people, and infrastructure are not changing.
-> Yes
* Have any CP/CPS changes occurred, or do you expect any change to occur as the result of this transaction?
-> No
* Are you undergoing any additional audits, or do you expect any changes in the status of your audits or compliance certificates as the result of this transaction?
-> No
* Please describe the management changes that will result from this transaction
-> No changes are expected in the management
* Please describe any changes to personnel that will result from this transaction
-> No changes are expected to personnel
* Please describe any changes to policies that will result from this transaction
-> No changes are expected to policies
* Please describe any changes to systems that will happen as a result of this transaction
-> No changes are expected to systems
* Please describe any other changes that will result from this transaction
-> No changes are expected
* Why was Mozilla not notified of this transaction 2 weeks ago when it was announced?
-> The operation is already public but it's necessary to wait until it has been done in the Spanish government's public registry. This point determines the effectiveness of the operation with third parties.
| Reporter | ||
Comment 2•7 years ago
|
||
Began a public discussion of this acquisition per policy section 8.1: https://groups.google.com/d/msg/mozilla.dev.security.policy/NyfFMsjnGrc/uypf71CyBwAJ
I noted that Camerfirma's annual audit reports are overdue.
Whiteboard: [ca-compliance] - Next Update - 01-July 2018 → [ca-compliance] - Next Update - 08-August 2018
| Reporter | ||
Comment 3•7 years ago
|
||
Asked for any final comments by 30-September.
Also referenced bug 1478933 on qualified audits.
Whiteboard: [ca-compliance] - Next Update - 08-August 2018 → [ca-compliance] - Next Update - 01-October 2018
| Reporter | ||
Comment 4•7 years ago
|
||
This acquisition discussion ended with a positive conclusion: https://groups.google.com/d/msg/mozilla.dev.security.policy/NyfFMsjnGrc/uypf71CyBwAJ
Status: NEW → RESOLVED
Closed: 7 years ago
QA Contact: kwilson
Resolution: --- → FIXED
Updated•3 years ago
|
Product: NSS → CA Program
You need to log in
before you can comment on or make changes to this bug.
Description
•