
Jump to: navigation, search

CA/Bug Triage

834 bytes added, 00:34, 11 January 2023
Compliance Problems and Incidents: Added mention of new whiteboard tags
Open Auditor Compliance bugs:
<br /><br />
The whiteboard tags for [ CA Program :: CA Certificate Compliance] areinclude:
* [ &#91;ca-compliance&#93;] -- For concerns about a CA's certificates failing to comply with [ Mozilla's CA Certificate Policy] and/or the [ CA/Browser Forum's Baseline Requirements], and it is not considered to be an [ imminent security concern].
* [ &#91;auditor-compliance&#93;] -- For concerns about an auditor failing to properly detect and report on CA compliance issues that occurred during one or more periods when the CA was audited.
* [ &#91;audit-delay&#93;] -- appended after [ca-compliance] when a CA is unable to provide audit statements within one year and 3 months of the previous audit period end date.
* [ &#91;covid-19&#93;] -- appended after [ca-compliance], [audit-delay], or [ca-revocation-delay] when delays are due to mandated restrictions regarding COVID-19.
New Whiteboard Tags include:
* [ca-misissuance] mis-issuance of a CA certificate
* [dv-misissuance] mis-issuance of a DV certificate
* [ov-misissuance] mis-issuance of an OV end-entity certificate
* [ev-misissuance] mis-issuance of an EV end-entity certificate
* [crl-failure] failure to provide certificate status via CRL; malformed, expired CRL
* [ocsp-failure] failure to provide certificate status via OCSP; malformed, expired OCSP
* [policy-failure] failure to update CP/CPS annually, failure to comply with practice in CP/CPS, misunderstanding requirements, failed implementation
* [disclosure-failure] failure to disclose an ICA, failure to report revocation of an ICA, non-disclosure-of-EV-sources, miscommunication, poor communication, etc.
* [audit-failure] failure to perform an audit, failure to upload audits, etc.
= Root Inclusion/Change requests and EV Treatment Enablement Requests=

Navigation menu