CA/BR Audit Guidance: Difference between revisions

Line 66: Line 66:


== WebTrust BR Audit Statement ==
== WebTrust BR Audit Statement ==
Mozilla accepts the following BR Criteria provided by [http://www.webtrust.org WebTrust]:
For a root certificate that has the Websites trust bit enabled, both the Webtrust [http://www.webtrust.org/homepage-documents/item54279.pdf Principles and Criteria for Certification Authorities 2.0] and the [http://www.webtrust.org/homepage-documents/item79806.pdf WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security – Version 2.0] audits are required.
* Principles and Criteria - SSL Baseline Requirements Version 1.1. (Amended) (Superseded)
* WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security – Version 2


The audit statement must specify the audit period dates, and that the audit was based on the "AICPA/CICA WebTrust for Certification Authorities – SSL Baseline Requirements Audit Criteria" or the "WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security". It is recommended that the audit statement include the version of the criteria that was used.
The audit statement must specify the audit period dates, and that the audit was based on the "AICPA/CICA WebTrust for Certification Authorities – SSL Baseline Requirements Audit Criteria" or the "WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security". It is recommended that the audit statement include the version of the criteria that was used.
Confirmed users, Administrators
5,526

edits