Viewable With ANY Browser

Note: My Web pages are best viewed with style sheets enabled.

Unrated

Certificate Authority Review Checklist

B. Public Access

Copyright © 2005, 2007 by David E. Ross

Version 2Jul07-1.0.3

Verification of the requirements in §B.1 will generally be done through interviews of the certificate authority's subscribers or becoming a subscriber. Verification of the requirements §B.2 may involve examination of the certificate authority's Web site and other public materials; it may also involve visiting or communicating with the certificate authority's physical site to request public information.

B.1 Access for Subscribers

B.2 Access for Both Subscribers and the General Public

B.1 Access for Subscribers
Req. #WTRequirementVerifiedComments
B.1.a8The privacy policy is available to subscribers.
B.1.b8The configuration-management policy is available to subscribers.
B.2 Access for Both Subscribers and the General Public
Req. #WTRequirementVerifiedComments
B.2.a8, 39The CP is available to subscribers and the general public.
B.2.b8, 39The CPS is available to subscribers and the general public.
B.2.c8The statement of risks (cited in §A.6.a) is available to subscribers and the general public.
B.2.d8The statement of the CA's liability (cited in §A.6.b) is available to subscribers and the general public.
B.2.e8The statement of the subscribers' liability (cited in §A.6.c) is available to subscribers and the general public.
B.2.fNoneThe statement of each subscriber's acceptance of liability (cited in §A.6.d) is available to those who present appropriate cause to request it.
B.2.g3Contact information is available to subscribers and the general public:
  • E-mail
  • postal
  • phone
B.2.h8, 11, 32A list of subscriber certificates is available to subscribers and the general public with the following information for each certificate:
  • name of certificate subscriber
  • certificate domain
  • certificate type
  • certificate user ID
  • certificate key ID
  • certificate fingerprints
  • issue date
  • expiration date
B.2.i11The information about a subscriber's certificate (see §B.2.h) that has expired is either
  • updated on the list of subscriber certificates to indicate expiration

    or

  • is moved to a list of expired certificates
B.2.j11, 33, 35A list of certificates revoked before their expiration dates is available to subscribers and the general public with the same identifying information as given in §B.2.h along with the reason for the revocation (see §A.2.o and §A.2.q).
B.2.k13, 32, 33, 35, 36Tools for verifying subscriber certificates are supported (e.g., certificate revocation list (CRL), online certificate status protocol (OCSP)) in a timely manner.
B.2.l7The fee schedule is available to subscribers and the general public.
B.2.mNoneThe CA promptly notifies all current subscribers of any breach of security (see §C.2).
B.2.nNoneThe CA makes available to the general public information about any breach of security (see §C.2).
B.2.oNoneThe CA makes available to the general public configuration-control logs and records (see §A.1.k).
B.2.p9This checklist (as completed by the reviewer) and the reviewer's attestation are available to subscribers and the general public.

Last updated 2 July 2007

Valid HTML 4.01