CA/Visa Issues: Difference between revisions

Line 4: Line 4:


==Issue A: Missing Baseline Requirements Audits (2014 - March 2016)==
==Issue A: Missing Baseline Requirements Audits (2014 - March 2016)==
Visa received an initial point-in-time Baseline Requirements audit (PITRA) on March 31, 2016 [https://bugzilla.mozilla.org/attachment.cgi?id=8795503 [1]]. This was more than two years past Mozilla’s deadline for BR compliance: “CAs with a root certificate that has the websites (SSL/TLS) trust bit enabled in Mozilla's CA Certificate Program shall have their SSL certificate issuance and operations audited according to the Baseline Requirements between February 15, 2013, and February 15, 2014.” [https://wiki.mozilla.org/CA:CertificatePolicyV2.1#Time_Frames_for_included_CAs_to_comply_with_the_new_policy [2]]
Visa received an initial point-in-time Baseline Requirements audit on March 31, 2016 [https://bugzilla.mozilla.org/attachment.cgi?id=8795503 [1]]. This was more than two years past Mozilla’s deadline for BR compliance: “CAs with a root certificate that has the websites (SSL/TLS) trust bit enabled in Mozilla's CA Certificate Program shall have their SSL certificate issuance and operations audited according to the Baseline Requirements between February 15, 2013, and February 15, 2014.” [https://wiki.mozilla.org/CA:CertificatePolicyV2.1#Time_Frames_for_included_CAs_to_comply_with_the_new_policy [2]]


==Issue B. Qualified Audits (2016 - Present)==
==Issue B. Qualified Audits (2016 - Present)==
136

edits