Closed
Bug 382624
Opened 19 years ago
Closed 17 years ago
CA Cert Policy: Improve definition of "independent"; add idea of "trustworthy"
Categories
(mozilla.org :: Governance, task)
mozilla.org
Governance
Tracking
(Not tracked)
RESOLVED
INVALID
People
(Reporter: gerv, Assigned: zak)
Details
Currently, the guidelines talk about an auditor having to be both "independent" and "competent". It has been suggested that the definition of independent should be changed to be more like that the inverse of the MPL's definition of You:
"For legal entities, "You" includes any entity which controls, is controlled by, or is under common control with You. For purposes of this definition, "control" means (a) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (b) ownership of more than fifty percent (50%) of the outstanding shares or beneficial ownership of such entity."
Additionally, a new "trustworthiness" requirement would be added, which would address some of the issues currently listed under "independent", such as being bound to render a true judgement. This is because one could imagine an auditor who was (under the above definition) independent and also competent, but may nevertheless always provide "the right result" on payment of a fee.
Gerv
| Reporter | ||
Comment 1•17 years ago
|
||
Discussion of this sort of thing now happens in mozilla.dev.security.policy, and documents are prepared on the wiki. So this information has been moved to:
https://wiki.mozilla.org/CA:Problematic_Practices
which seems the right sort of place for it to be if it's going to be taken into account for future policy revisions.
There's no good resolution to use; INVALID will have to do.
Gerv
Status: NEW → RESOLVED
Closed: 17 years ago
Resolution: --- → INVALID
You need to log in
before you can comment on or make changes to this bug.
Description
•