Trustis has applied to add the “Trustis FPS Root CA” root certificate,
and turn on the websites and email trust bits.
Trustis is a commercial CA operating primarily in the UK and Europe.
The request is documented in the following bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=577665
And in the pending certificates list here:
http://www.mozilla.org/projects/security/certs/pending/#Trustis
Summary of Information Gathered and Verified:
https://bugzilla.mozilla.org/attachment.cgi?id=587468
Noteworthy points:
* The primary documents are the CP and Minimum Enrolment Requirements.
The documents are in English.
Document Repository:
http://www.trustis.com/pki/fpsia/
Minimum Enrolment Requirements:
http://www.trustis.com/pki/fpsia/policy/T-0104-002-ATL-013-Trustis-FPS-Minimum-Enrolment-Requirements-V3_0.pdf
Certificate Policy:
http://www.trustis.com/pki/fpsia/policy/T-FPS-CP-V1-04.pdf
Issuing Authority PKI Disclosure Statement:
http://www.trustis.com/pki/fpsia/policy/disclosure.htm
Subscriber Agreement:
http://www.trustis.com/pki/fpsia/policy/subscriber-agreement.htm
* CA Hierarchy Diagram:
https://bugzilla.mozilla.org/attachment.cgi?id=268357
* This root signs internally-operated Issuing CAs that sign end-entity
certs.
** The Trustis FPS Enterprise Authority is the subCA used for issuing
general SSL certificates.
** The Trustis DTP Issuing Authority does not issue SSL certificates.
** The Trustis Healthcare Issuing Authority issues SSL certificates to
UK NHS facilities.
* All subCAs issuing certificates must do so in accordance with the UK
Government Authentication Framework - Level 2. This is required for all
certificates from all of the FPS subCAs be they individual or SSL. In
the case of SSL, this means certs issued are of level 3 or higher.
Domains are validated but a number of other criteria relating to the
organization and the individual representing the organization must also
be satisfied.
UK Government Authentication Framework (GAF) – HMG Minimum Requirements
for Verification:
** Individuals:
http://www.cabinetoffice.gov.uk/media/252559/regindividualsv2.pdf
** Organizations:
http://www.cabinetoffice.gov.uk/media/252565/registra_orgs_v2.pdf
* The request is to turn on the Websites and Email trust bits.
* The following quotes are from the Minimum Enrolment Requirements
document:
** “Trustis FPS issues certificates to a number of levels of assurance
and authentication. In all cases certificates issued shall fulfil the
Standards of HMG Assurance Framework, specifically:
- HMG Minimum Requirements for the Verification of the Identity of
Individuals V2
- HMG Minimum Requirements for the Verification of the Identity of
Organisations V2 at level two.”
** “Note that a formal documented existing relationship with the RA may
be used in lieu of / with other evidence if the RA already has strong
confidence in the identity of the registrant organisation. Underlying
identification checks must have been previously performed and it is
essential to ensure that information used is up-to-date.”
** For Organization Representative, Type of Evidence Required:
“General person acceptable evidence Plus:
- organisational acceptable evidence
- evidence of affiliation to the organisation
- evidence of authority to act on behalf of the organisation
- verification of the representative through "back contact" with the
organization”
** “The registration data for the domain is collected from approved
and/or third party public sources (WHOIS) and corroborated against the
information verified as part of the individual or organisation
registration submitted in the application.
… Where third party or public evidence does not provide corroboration of
ownership of a domain, or an organisation or individual controls a
domain not registered with it. Certified written evidence of
ownership/control must be provided. This is verified and/or corroborated
with the registered owner of the domain.”
** “Certificates are not issued on the basis of email address only.
Applicants must fulfil all identity verification requirements AND prove
ownership of the email address to be identified in the certificate. …
Back contact using the declared email address and or third party
corroboration is undertaken as part of the enrolment process.”
* EV Policy OID: Not requesting EV treatment at this time.
* Test Websites:
https://www.trustis.com/
* CRL:
http://www.trustis.com/pki/fps/crl/fpsder.crl
http://www.trustis.com/pki/trustis-ssl/crl/ee.crl (NextUpdate: 24 hours)
** CP section 4.4.9: CRL for end-entity certs is scheduled at least
every 24 hours.
* OCSP: Not provided
* Audit: Audits have been performed by KPMG according to the WebTrust CA
criteria. The audit report is posted on the
cert.webtrust.org website:
https://cert.webtrust.org/ViewSeal?id=1120
Potentially Problematic Practices
(
http://wiki.mozilla.org/CA:Problematic_Practices):
* Delegation of Domain / Email validation to third parties
** Registration Authorities are used as per section 1.3.2.3 of the CP.
** Registration Authorities (RAs) are permitted to conduct registrations
for a limited, defined and controlled number and type of end-entities.
The RAs have to operate in compliance with the Certificate Policy (CP)
and Certification Practice Statement (CPS) and also the declared
authentication levels for the Trustis FPS services, which are set at HMG
Authentication Framework Level 2 or higher. These are controlled under
the CP, a variety of internal and third party audits and the specific
contractual relationship.
This begins the discussion of the request from Trustis to add the
“Trustis FPS Root CA” root certificate, and turn on the websites and
email trust bits. At the conclusion of this discussion, I will provide a
summary of issues noted and action items. If there are no outstanding
issues, then this request can be approved. If there are outstanding
issues or action items, then an additional discussion may be needed as
follow-up.
Kathleen