Policy 2.7.1: Published

154 views
Skip to first unread message

Ben Wilson

unread,
Apr 12, 2021, 7:04:04 PM4/12/21
to dev-secur...@mozilla.org
Version 2.7.1 of the Mozilla Root Store Policy is now available at:

dr. Szőke Sándor

unread,
Oct 18, 2021, 1:44:06 PM10/18/21
to Ben Wilson, dev-secur...@mozilla.org

Hi Ben,

 

I hope that you are doing well.

I would like to ask your help regarding an Audit Case.

 

I got the Attestation Letters from our auditor for our root certificates today.

 

I opened the first Audit Case (00000853) for our RSA based root as follows:

 

https://ccadb.force.com/s/case/5004o00000MUqJfAAL/2021-audit-microsec-eszigno-root-ca-2009?reportFilters=%5B%7B%22operator%22%3A%22equals%22%2C%22value%22%3A%22001o000000HsfpD%22%2C%22column%22%3A%22PARENT_ID%22%7D%5D

 

When I try to run the Audit Letter Validation I get an error message as you can see in the attached file.

 

It seems that the program can’t find the correct audit statement in the Audit Letter:

https://www.hunguard.hu/wp-content/uploads/2021/10/Attestation_letter_004_RSA_v10_ds.pdf

 

The AL says:

The audit was performed according to the European Standards “ETSI EN 319 411-2, V2.3.1 (2021-05)”, “ETSI EN 319 411-1, V1.3.1 (2021-05)”, and “ETSI EN 319 401, V2.3.1 (2021-05)” considering the requirements of the “ETSI EN 319 403, V2.2.2 (2015-08)” for the Trust Service Provider Conformity Assessment.

 

The Error message mentions only older versions of the ETSI standard:

 

EN 319 411-1 V1.1.1

EN 319 411-1 V1.2.2

 

Can it cause the problem?

 

I think that the requested information is present in our Attestation letter, probably the format or the arrangement is not exactly as expected.

 

Please help me how to proceed.

 

Best Regards,

 

Sándor

 

 

Dr. Sándor SZŐKE

dep. Director of eIDAS Trust Services

 

 

Microsec Ltd.  |  Ángel Sanz Briz Road 13.

Budapest, H-1033 Hungary
Graphisoft Park Southern Area, Building C, 3th floor

T: +36 1 802-4418  |   +36 1 505-4477 / 488
sandor...@microsec.com
microsec.com

 

image001.png
JixiService.pdf

Ben Wilson

unread,
Oct 18, 2021, 9:29:18 PM10/18/21
to dr. Szőke Sándor, dev-secur...@mozilla.org
Dear Sandor,
I have added the new versions of the ETSI EN 411-1 and EN 411-2 to the CCADB.
Thanks,
Ben
Reply all
Reply to author
Forward
0 new messages