ACCV has applied to add the �ACCVRAIZ1� root certificate and enable all
three trust bits. This root certificate will eventually replace the
�Root CA Generalitat Valenciana� root certificate that was included via
bug #274100.
The ACCV CA is operated by a government agency of Spain, and focuses its
activities mainly in Spain but is also collaborating in international
recognition of certificates. ACCV issues certificates for citizens for
their personal use and for its relations with the public administration
and business.
The request is documented in the following bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=811352
And in the pending certificates list here:
http://www.mozilla.org/projects/security/certs/pending/#ACCV
Summary of Information Gathered and Verified:
https://bugzilla.mozilla.org/attachment.cgi?id=727980
Noteworthy points:
* The primary documents are the CPS and CP for each certificate usage.
The CP documents are in Spanish, and the CPS has been translated into
English.
Document Repository:
http://www.accv.es/quienes-somos/practicas-y-politicas-de-certificacion/
CPS (EN):
http://www.accv.es/fileadmin/Archivos/Practicas_de_certificacion/ACCV-CPS-V3.0-EN.pdf
SSL CP:
http://www.accv.es/fileadmin/Archivos/Politicas_pdf/ACCV-CP-03V3.0-c.pdf
Code Signing CP:
http://www.accv.es/fileadmin/Archivos/Politicas_pdf/ACCV-CP-04V3.0-c.pdf
Qualified Certs CP for Public Employees:
http://www.accv.es/fileadmin/Archivos/Politicas_pdf/ACCV-CP-13V4.0-c.pdf
Qualified Certs CP for Citizens:
http://www.accv.es/fileadmin/Archivos/Politicas_pdf/ACCV-CP-07V5.0-c.pdf
The �ACCVRAIZ1� root certificate has signed two internally-operated
subordinate CA certificates, ACCVCA-110 and ACCVCA-120.
This request is to enable all three trust bits.
* Translation of SSL CP section 3.2.3: The authentication of the
identity of the requesting a certificate shall be made by the use of
recognized certificate of citizen or public employee of the ACCV to sign
the application server certificate with SSL support. The applicant must
also submit the necessary documentation to determine the ability of
represent the Public or private entity that owns the server that is
intended the certificate. This submission will be carried out using
telematic means that the ACCV available to users. The ACCV check both
data using for it the information available to personnel records and
domain, requiring the applicant or the Administration represented
clarifications or additional documents may be required. In case private
entities require authorization information from the applicant.
* Translation from SSL CP section 3.2.4 Checking the application domain
The ACCV verify that domains and addresses associated with the
certificate belong to the applicant by consulting the records assigned
by ICANN / IANA. This check will be made with using records WHOIS
queries enabled by the organization Red.es
http://www.nic.es or
equivalent in national domains or those provided by Verisign for generic
domains (whois.verisigngrs. com) .
Besides WHOIS query connection will be tested by secure protocol (eg
HTTPS) with the domain in question if possible and test DNS response.
For any irregularity ACCV contact the applicant for the license and the
issuance of the certificate will be suspended until its cure. If this is
not remedied within the period of one month the application would be denied.
In the verification process, the information obtained from the WHOIS or
equivalent records was compared with that provided by the applicant,
sending personalized emails to technical and administrative contacts
obtained from both sources and if necessary to ensure that the data is
correct and that domain ownership is confirmed is make phone calls
asking for clarification.
* Snippets of Translations from Qualified Certs CP for Public Employees:
** Section 3.2.2: The license application defined in this policy is
limited Certification to public authorities or administrations with
which agreement has been established certification contract or some
other formula that implements the service by the ACCV.
** Section 3.2.3: The determination of the public employee status is the
responsibility of the Administration or Public entity applicant, which
shall check the condition of public employee, either in its database, if
it is updated, or by requesting the document by which the subscriber has
purchased This condition, if not any indication as to the Administration
or Public Entity applicant.
� The Autoritat of Certification of the Valencia only guarantee that the
email address stated on the certificate was provided by the
Administration or public entity that owns the subscriber in the upon
finalization of your application and / or shown as linked to subscriber
bases personal data of the Government or the Civil Service to which
belongs applicant.
* Civil servants certificates are issued from the official lists
supplied by the public administration concerned. These official lists
are drawn from selective processes with maximum guarantees (determine
who is a civil servant) and involve a process in person at the
registration point of administration. Public administration provides its
employees with email accounts for his work as a civil servant. These
email accounts are corporate and internally generated. The ACCV accepts
these mail accounts because they are imposed by the administration and
not by the user.
* Snippets of Translations from Qualified Certs CP for Citizens:
** Section 3.2.2 : The application for certificates associated to this
Certificate Policy is limited to public entities or administrations
which have established a certification agreement, contract or some other
formula that supports the ACCV service provision.
The public entity or administration identification process will be held
in the organization enrollment to be signed by an authorized
representative of the entity or administration.
** Section 3.2.3: The certificate applicant identity authentication will
be made in person while applying or during the certificate delivery.
Thus, Registration is delegated to the certificate issuing entity which
signed an agreement, contract or some other formula that supports the
ACCV service provision.
Presence of the civil servant to whom a certificate is issued will not
be required when his/her identity and civil servant status are already
recorded in the Personnel Registry of the Public or Corporate Entity or
Public Administration which the civil servant belongs to and where
his/her application is directed to.
The applicant public entity or administration has the entire
responsibility of determining the civil servant status. The public
entity or administration will check the public servant status in its
database if it is updated or by requesting a document where the
subscriber�s status is stated in case that the applicant public entity
or administration has not this record.
These certificates include the subscriber�s email address as a necessary
element to support digital signature and email encryption operations.
However, the Autoritat de Certificaci� de la Comunitat Valenciana does
not guarantee that this electronic address is linked to the certificate
subscriber, thus the confidence that this email is linked to the
certificate subscriber relates to the relying party only. The Autoritat
de Certificaci� de la Comunitat Valenciana just guarantees that the
email stated in the certificate was provided by the Administration or
Public Entity which the subscriber belonged to at the time that the
application was made and/or that this email is linked to the subscriber
in the Valencia Government or other Public Administration personnel data
base that the applicant belongs to.
** Section 4.1: This certificate request is responsibility of the Public
Entity or Administration which shall verify the certificate owner�s
civil servant status by checking their organization personnel registry.
* Translation of Code Signing CP section 3.2.3: The authentication of
the identity of the applicant for a certificate shall be made by the use
of recognized certificate of citizen or public employee of the ACCV to
sign the certificate request for code signing.
The applicant must also submit the necessary documentation to determine
the capacity of representing the public administration or private entity
on behalf of which, ultimately, is going to issue the certificate. This
Presentation is telematically using the means and Technology Agency of
Electronic Certification available to users.
Technology Agency of Electronic Certification and verify both data, the
ability to re-presentation of the applicant and the veracity of the data
of the company or organization, using information available from
personnel records, requiring the applicant or the Administration
represented the clarifications or additional documents may be required.
In case of private entities, will require information on the
authorization of the applicant and the information of the company
creating searchable in the appropriate register.
* EV Policy OID: Not requesting EV treatment.
* Root Cert URL
http://www.accv.es/fileadmin/Archivos/certificados/ACCVRAIZ1.crt
* Test Website:
https://ulik2.accv.es/
* CRL
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
http://www.accv.es/fileadmin/Archivos/certificados/accvca110_der.crl
(NextUpdate: 3 days)
http://www.accv.es/fileadmin/Archivos/certificados/accvca120_der.crl
(NextUpdate: 3 days)
CPS section 4.9.9: ACCV shall publish a new CRL in its repository at
maximum intervals of 3 hours, even if there have been no modifications
to the CRL (changes to the status of certificates) during the
aforementioned period.
* OCSP:
http://ocsp.accv.es
* Audit: ACCV is audited according to the WebTust CA criteria, and audit
statements are posted on the
webtrust.org website.
https://cert.webtrust.org/ViewSeal?id=1352
* Potentially Problematic Practices
(
http://wiki.mozilla.org/CA:Problematic_Practices)
** Delegation of validation to third parties.
*** CPS section 1.3.2: Bodies of the Autonomous Government of Valencia
as well as other entities can be Registration Authorities provided that
the corresponding collaboration agreement has been entered into. These
Registration Authorities are referred to as User Registration Points or
PRUs in the documentation relating to the Certification Authority of the
Community of Valencia, and they are entrusted with confirmation of the
requester�s identity and delivery of the certificate.
*** CPS section
5.2.1.7: Auditor� must verify all aspects mentioned in
the security policy, copies policies, certification practices,
Certification Policies, etc. in the group of ACCV systems and within the
ACCV personnel, as well as in the PRUs.
*** CPS section 9.6.2: The persons that operate in the RAs integrated
into the hierarchy of the ACCV � User Registration Point Operators � are
obliged to:
* Carry out their operations in accordance with this CPS.
* Carry out their operations in accordance with the Certification Policy
that is applicable for the type of certificate requested on each occasion.
* Exhaustively verify the identity of the persons granted the digital
certificate processed by the Operators, for which purpose they will
require the physical presence of the requester and the presentation of
their current National ID Card (not a photocopy), or a Spanish passport.
Non-Spanish users must present a Residence Card/Foreigner�s ID Card.
This begins the discussion of the request from ACCV to add the
�ACCVRAIZ1� root certificate and enable all three trust bits. At the
conclusion of this discussion I will provide a summary of issues noted
and action items. If there are outstanding issues, then an additional
discussion may be needed as follow-up. If there are no outstanding
issues, then I will recommend approval of this request in the bug.
Kathleen