[cabfpub] Does the CA/Browser Forum provide guidance on the Baseline Requirements?

Moudrick M. Dadashov md at ssc.lt
Sat Feb 25 04:08:31 UTC 2017




On 2/25/2017 4:54 AM, Ryan Sleevi via Public wrote:
> Recently, a question was received from an auditor requesting 
> clarification from the CA/Browser Forum about a specific requirement 
> in the Baseline Requirements.
> At least two long-standing members advanced a position that the role 
> of the Forum is not to provide guidance or advice on the 
> interpretation of the Baseline Requirements. In effect, that it is up 
> to individual readers - or, for the sake of CAs, auditors - to 
> determine what is meant by these Requirements and how to apply them.
> These members suggested that any guidance the Forum offers is 
> non-binding, in that it is ultimately up to auditors to determine what 
> is meant.
> I am deeply concerned and dismayed by such an answer, and expressed 
> this to these members. I believe that this is a core role of the 
> CA/Browser Forum: To ensure the Requirements are clear and unambiguous 
> whenever possible, to provide guidance as to the intent and 
> interpretation when necessary, and to strive to resolve any ambiguity 
> in the documents themselves whenever possible.
> I'm curious if any other members share the viewpoint that the Forum 
> does not and should not provide guidance as to the meaning or intent 
> with respect to the documents, and if so, how best we can correct and 
> resolve this difference of viewpoints regarding the role and 
> obligation of the Forum.
> _______________________________________________
> Public mailing list
> Public at cabforum.org
> https://cabforum.org/mailman/listinfo/public

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/public/attachments/20170225/34e64cc4/attachment-0003.html>

More information about the Public mailing list