CA/BR Audit Guidance: Difference between revisions

m
Line 78: Line 78:
Definition: A ''qualified'' audit statement is issued when the auditor encountered one or more instances in which the CA does not comply with the audit criteria, however the CA is in compliance with the rest of the audit criteria.
Definition: A ''qualified'' audit statement is issued when the auditor encountered one or more instances in which the CA does not comply with the audit criteria, however the CA is in compliance with the rest of the audit criteria.


==== Extended Validation (EV) ====
=== Extended Validation ===
* PROPOSED Text -- under discussion in mozilla.dev.security.policy
* '''PROPOSED Text''' -- under discussion in mozilla.dev.security.policy


If the root certificate is enabled for EV treatment, then the following three public-facing audit statements are required annually:
If the root certificate is enabled for EV treatment, then the following three public-facing audit statements are required annually:
Confirmed users, Administrators
5,526

edits