Skip to content

Commit

Permalink
Addresses Issue mozilla#152 - EV certificate audit scope
Browse files Browse the repository at this point in the history
  • Loading branch information
BenWilson-Mozilla committed Oct 15, 2020
1 parent 5dec00e commit c1acc76
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions rootstore/policy.md
Expand Up @@ -236,7 +236,7 @@ apply (see section 3.1.1 for specific version numbers):

* [WebTrust for CAs][WebTrust-2.0]
* [WebTrust for CAs - SSL Baseline with Network Security][WebTrust-BRs]
* [WebTrust for CAs - EV SSL][WebTrust-EV] (if capable of issuing EV certificates)
* [WebTrust for CAs - EV SSL][WebTrust-EV] if capable of issuing EV certificates (i.e. a subordinate CA under an EV-enabled root that contains no EKU or the id-kp-serverAuth EKU or anyExtendedKeyUsage EKU, and a certificatePolicies extension that asserts the CABF EV OID of 2.23.140.1.1, the anyPolicy OID, or the CA's EV policy OID)

* For the email trust bit, a CA and all subordinate CAs technically capable
of issuing email certificates must have all of the following audits:
Expand All @@ -258,7 +258,7 @@ If being audited to the ETSI criteria, the following audit requirements apply
* [ETSI EN 319 411-2][ETSI-319-411-2] (QCP-w)

An audit showing conformance with the EVCP policy is required if a CA is capable of issuing EV
certificates.
certificates (i.e. a subordinate CA under an EV-enabled root that contains no EKU or the id-kp-serverAuth EKU or anyExtendedKeyUsage EKU, and a certificatePolicies extension that asserts the CABF EV OID of 2.23.140.1.1, the anyPolicy OID, or the CA's EV policy OID).

* For the email trust bit, a CA and all subordinate CAs technically
capable of issuing email certificates must have one of the
Expand Down

0 comments on commit c1acc76

Please sign in to comment.