CA/Root Store Policy Archive: Difference between revisions

→‎To Be Discussed: Add a note about providing translations
(→‎To Be Discussed: Add a note about providing translations)
Line 134: Line 134:
# If a government CA does not use a 3rd-party auditor, then the domains that they can issue for should be constrained.
# If a government CA does not use a 3rd-party auditor, then the domains that they can issue for should be constrained.
#* Note that when scrolling through the Auditor column in the [http://www.mozilla.org/projects/security/certs/included/index.html included spreadsheet] it looks like distinguishing based on the auditing would only currently find one included CA. However, this still may be worth considering, as there are other CAs who have applied for inclusion and have their audits done by internal government organizations.
#* Note that when scrolling through the Auditor column in the [http://www.mozilla.org/projects/security/certs/included/index.html included spreadsheet] it looks like distinguishing based on the auditing would only currently find one included CA. However, this still may be worth considering, as there are other CAs who have applied for inclusion and have their audits done by internal government organizations.
# Add a requirement for CAs to provide English-translated versions of their complete CP / CPS


==== Will NOT Do ====
==== Will NOT Do ====
21

edits