CA:CommonCADatabase: Difference between revisions

Creating initial text
(Creating initial text)
(Creating initial text)
Line 13: Line 13:


= Getting Started =
= Getting Started =
After you receive email with your CA Community License, you may login to the Common CA Database by:
After you receive email with your CA Community License, you may login to the Common CA Database as follows:
# Browse to: https://mozillacacommunity.force.com/
# Browse to: https://mozillacacommunity.force.com/
# Enter your Username; the email address for which your Community User License was issued
# Enter your Username; the email address for which your Community User License was issued
Line 19: Line 19:
# Click on the "Log in to CA Community" button
# Click on the "Log in to CA Community" button


Upon initial login you will see a row with three tabs:
Upon initial login you will see a row with six tabs:
# Home
# CA Owners/Certificates
# CA Owners/Certificates
#* Click on "CA Owners/Certificates" tab, then in "View:" select "Community User's CA Owners/Certificates" and click on "Go!". This will list the CA Owner and all of the root and intermediate certificates associated with your account. Click on the "CA Owner/Certificate Name" to view the record. Within the record you will see an Account Hierarchy section, where you can click on each root or intermediate certificate record to view the data.  
#* Click on "CA Owners/Certificates" tab, then in "View:" select "Community User's CA Owners/Certificates" and click on "Go!". This will list the CA Owner and all of the root and intermediate certificates associated with your account. Click on the "CA Owner/Certificate Name" to view the record. Within the record you will see an Account Hierarchy section, where you can click on each root or intermediate certificate record to view the data.  
#* Click on "CA Owners/Certificates" tab, then in "View:" select "All Included CA Owners" and click on "Go!". You will see all of the CAs who have root certificates included in the NSS root store. Click on the CA Owner Name, to view the record.
#* Click on "CA Owners/Certificates" tab, then in "View:" select "Community User's Intermediate Certs" and click on "Go!". This will list the intermediate certificates associated with your account. Click on the "CA Owner/Certificate Name" to view the record.
# Contacts
# Contacts
#* Click on "Contacts" tab, then in "View:" select "All Contacts" and click on "Go!". Click on the Name to view the contact record.  
#* Click on "Contacts" tab, then in "View:" select "All Contacts" and click on "Go!". Click on the Name to view the contact record.  
#* Note: If any of the contact information for your CA needs to be updated, then send email to Kathleen. CA Community licenses do not enable the CA to directly modify their contact data.
# Cases
#* Click on "Cases" tab, then "My Cases" and click on "Go!".
# CA Communications (Page)
#* This may be used when a root store operator polls their CA members for information.
# Reports
# Reports
#* Click on "Reports" tab, then click on the "CA Community Reports" link along the left column, then click on one of the reports in the list. Whenever you click on the "Reports" tab it will list the reports that you have recently viewed. You will need to click on the "CA Community Reports" link to see all of the reports that are available to you.
#* Click on "Reports" tab, then click on the "CA Community Reports" link along the left column, then click on one of the reports in the list. Whenever you click on the "Reports" tab it will list the reports that you have recently viewed. You will need to click on the "CA Community Reports" link to see all of the reports that are available to you.


Important Notes:
Important Notes:
* Each Owner/Certificate record has a "CA Owner/Certificate Name" field. For a certificate record, the value of this field is usually the Certificate '''Subject''' Common Name of the certificate. For a CA Owner record, this field displays the CA's name. (We cannot change the title of the field in the page, due to the way we are using it in Salesforce.)
* Each Owner/Certificate record has a "CA Owner/Certificate Name" field. For a certificate record, the value of this field is usually the Certificate '''Subject''' Common Name of the certificate. For a CA Owner record, this field displays the CA's name. (We cannot change the title of the field in the page, due to the way we are using it in the CRM.)
* Each Certificate record has a "Parent CA Owner/Certificate" field. For an intermediate certificate record the value of the field should be the Certificate '''Issuer''' Common Name. For a root certificate record the value of the field will be the name of the CA owner. (We cannot change the title of the field in the page, due to the way we are using it in Salesforce.)
* Each Certificate record has a "Parent CA Owner/Certificate" field. For an intermediate certificate record the value of the field should be the Certificate '''Issuer''' Common Name. For a root certificate record the value of the field will be the name of the CA owner. (We cannot change the title of the field in the page, due to the way we are using it in the CRM.)
* CA Community Users cannot modify the records for: Owner, Root Certificate, and Contact. Only the [[Modules/All#CA_Certificates|CA Certificates Module Owner and Peers]] can modify these records.
* CA Community Users cannot modify the records for: Owner, Root Certificate, and Contact. Only the Root Store Members can modify these records.
* CA Community Users can only modify the intermediate certificate records for their CA.
* CA Community Users can only modify the intermediate certificate records for their CA.
* The Intermediate certificate records have a Status field that may not be modified by CAs.
* When PEM data is provided, the certificate details in the record may not be modified.
* When PEM data is provided, the certificate details in the record may not be modified.
* PEM data must be provided for every intermediate certificate (chaining up to a root certificate in Mozilla's program) that is not [[CA:CertificatePolicyV2.1#Technical_Constraints_or_Auditing.2FDisclosure_of_Intermediate_Certificates|Technically Constrained]] via Extended Key Usage and Name Constraint settings. Policy documentation and audit statements must also be provided for these non-technically-constrained intermediate certificates, as per section 10 of [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ Mozilla's CA Certificate Inclusion Policy].
Confirmed users, Administrators
5,526

edits