Confirmed users, Administrators
5,526
edits
Line 99: | Line 99: | ||
=== Documents === | === Documents === | ||
According to [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ Mozilla's CA Certificate Policy], section 10: "For a certificate to be considered publicly disclosed and audited, the following information MUST be provided: ... corresponding Certificate Policy or Certification Practice Statement used by the subordinate CA; and Annual public attestation of conformance to the stated certificate verification requirements and other operational criteria by a competent independent party or parties with access to the details of the subordinate CA’s internal operations." | |||
* If you don't already have a Bugzilla account, [https://bugzilla.mozilla.org/createaccount.cgi create an account] for yourself. | |||
** Note that you must supply an email address when creating an account. Be sure to use an email address that you regularly monitor, so you will be notified whenever a Bugzilla Bug that you create is modified. | The CP/CPS and Audit information for publicly-disclosed and audited intermediate certificates should be provided on the subordinate CA's website, or the CA's website. However, if needed, you can use Bugzilla to provide the CP/CPS and Audit documents as follows. | ||
* [https://bugzilla.mozilla.org/enter_bug.cgi?alias=&assigned_to=kwilson@mozilla.com&blocked=&bug_file_loc=http%3A%2F%2F&bug_severity=enhancement&bug_status=NEW&comment=The%20purpose%20of%20this%20bug%20is%20to%20store%20documents%20related%20to%20the%20publicly%20disclosed%20and%20audited%20intermediate%20certificates%20chaining%20up%20to%20%5Byour%20CA%27s%20name%5D%20root%20certificates.&component=CA%20Certificates&contenttypeentry=&contenttypemethod=autodetect&contenttypeselection=text%2Fplain&data=&dependson=&description=&flag_type-4=X&flag_type-481=X&flag_type-486=X&flag_type-530=X&flag_type-536=X&flag_type-541=X&flag_type-542=X&flag_type-543=X&form_name=enter_bug&keywords=&maketemplate=Remember%20values%20as%20bookmarkable%20template&op_sys=All&priority=--&product=mozilla.org&qa_contact=ca-certificates%40mozilla-org.bugs&rep_platform=All&short_desc=Documents%20for%20%5Byour%20CA%27s%20name%5D%20intermediate%20certificates&target_milestone=---&version=other Create a Bugzilla Bug] -- This link will create a bug with the following fields set: | |||
** Product: mozilla.org | # Create a Bugzilla Bug | ||
** Component: CA Certificates | #* If you don't already have a Bugzilla account, [https://bugzilla.mozilla.org/createaccount.cgi create an account] for yourself. | ||
** Version: Other | #** Note that you must supply an email address when creating an account. Be sure to use an email address that you regularly monitor, so you will be notified whenever a Bugzilla Bug that you create is modified. | ||
** Severity: enhancement | #* [https://bugzilla.mozilla.org/enter_bug.cgi?alias=&assigned_to=kwilson@mozilla.com&blocked=&bug_file_loc=http%3A%2F%2F&bug_severity=enhancement&bug_status=NEW&comment=The%20purpose%20of%20this%20bug%20is%20to%20store%20documents%20related%20to%20the%20publicly%20disclosed%20and%20audited%20intermediate%20certificates%20chaining%20up%20to%20%5Byour%20CA%27s%20name%5D%20root%20certificates.&component=CA%20Certificates&contenttypeentry=&contenttypemethod=autodetect&contenttypeselection=text%2Fplain&data=&dependson=&description=&flag_type-4=X&flag_type-481=X&flag_type-486=X&flag_type-530=X&flag_type-536=X&flag_type-541=X&flag_type-542=X&flag_type-543=X&form_name=enter_bug&keywords=&maketemplate=Remember%20values%20as%20bookmarkable%20template&op_sys=All&priority=--&product=mozilla.org&qa_contact=ca-certificates%40mozilla-org.bugs&rep_platform=All&short_desc=Documents%20for%20%5Byour%20CA%27s%20name%5D%20intermediate%20certificates&target_milestone=---&version=other Create a Bugzilla Bug] -- This link will create a bug with the following fields set: | ||
** Platform: All | #** Product: mozilla.org | ||
** OS: All | #** Component: CA Certificates | ||
** Summary: Documents for [your CA's name] intermediate certificates | #** Version: Other | ||
** Description: The purpose of this bug is to store documents related to the publicly-disclosed and audited intermediate certificates chaining up to the following root certificate(s) [list root certs]. | #** Severity: enhancement | ||
* If needed, you can manually create the bug: Go to the [https://bugzilla.mozilla.org/enter_bug.cgi Bug Entry Page,] click on Other Products, and select mozilla.org under Other. Then select the fields as listed above. | #** Platform: All | ||
#** OS: All | |||
#** Summary: Documents for [your CA's name] intermediate certificates | |||
#** Description: The purpose of this bug is to store documents related to the publicly-disclosed and audited intermediate certificates chaining up to the following root certificate(s) [list root certs]. | |||
#* If needed, you can manually create the bug: Go to the [https://bugzilla.mozilla.org/enter_bug.cgi Bug Entry Page,] click on Other Products, and select mozilla.org under Other. Then select the fields as listed above. | |||
# Attach the document(s) to the bug | |||
# Copy-and-paste the link to the Bugzilla Bug attachment into the corresponding field in Salesforce | |||
== Audit Information == | == Audit Information == |