Confirmed users, Administrators
5,526
edits
(Clarified that re-issued root certificates also still need to go through the evaluation/approval/inclusion process. And re-organized the top part of this section.) |
m (Updated due to MDSP migration) |
||
Line 29: | Line 29: | ||
# A representative of Mozilla [[CA/Application_Verification#Information_Verification|verifies the information provided by the CA]]. | # A representative of Mozilla [[CA/Application_Verification#Information_Verification|verifies the information provided by the CA]]. | ||
# A representative of Mozilla or of the CA Community (as agreed by a Mozilla representative) performs a [[CA/Application_Verification#Detailed_Review|detailed review of the CA’s CP/CPS and audit documents]]. During this phase, the CA may be required to update their CP/CPS and audit documents to become fully aligned with [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/ Mozilla's Root Store Policy]. | # A representative of Mozilla or of the CA Community (as agreed by a Mozilla representative) performs a [[CA/Application_Verification#Detailed_Review|detailed review of the CA’s CP/CPS and audit documents]]. During this phase, the CA may be required to update their CP/CPS and audit documents to become fully aligned with [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/ Mozilla's Root Store Policy]. | ||
# A representative of Mozilla starts the [[CA/Application_Verification#Public_discussion|public discussion]] for the CA in the [https:// | # A representative of Mozilla starts the [[CA/Application_Verification#Public_discussion|public discussion]] for the CA in the [https://groups.google.com/a/mozilla.org/g/dev-security-policy MDSP mailing list], stating Mozilla’s intent to approve the request and initiating a 3 week comment period. If no concerns are raised during that time period, then the representative of Mozilla will close the discussion and the request may proceed to the approval phase. | ||
# A representative of the CA responds to questions and concerns posted during the public discussion of the CA's request. | # A representative of the CA responds to questions and concerns posted during the public discussion of the CA's request. | ||
# A representative of Mozilla summarizes the discussion and resulting decisions or action items. | # A representative of Mozilla summarizes the discussion and resulting decisions or action items. |