5 ms·
Do you know any details about the auditing process that the independent company would perform of a CA? Since the whole signing SSL business is built around kee
by sr3d 16y ago
Do you know any details about the auditing process that the independent company would perform of a CA? Since the whole signing SSL business is built around keeping a 256-byte or so private key private then this file would probably be protected pretty well.
- viraptor 16y agoHave a look at http://wiki.cacert.org/InclusionStatus http://wiki.cacert.org/InclusionStatus and follow the links in comments. There's a lot of information about different audits done and planned, lists of rules, discussions about what happened in the past, etc. Direct link to Mozilla rules is http://www.mozilla.org/projects/security/certs/policy/ http://www.mozilla.org/projects/security/certs/policy/
- morgs 16y agoIt's the WebTrust audit for Certification Authorities: http://www.webtrust.org/certauth_fin.htm http://www.webtrust.org/certauth_fin.htm (warning: PDF)