3 ms·
Much of that response is misleading. It does make a technically correct claim that QWACs are currently accepted by browsers. However, the reality is that QWACs
by jsmith45 3y ago
Much of that response is misleading.
It does make a technically correct claim that QWACs are currently accepted by browsers. However, the reality is that QWACs are only accepted by browsers if the issuer fully complies with both CAB Forum baseline requirements, and Root program rules. The entire purpose of the clause in question is effectively to ensure an EU Bureaucracy is responsible for for setting rules instead of CAB Forum and Root programs.
Another example it is absolutely true that the eIDAS 2.0 regulars impose some certain weaker security requirements than current browsers.
A trivial example is that the response claims QWACs will comply with Brower's Certificate Transparency standards, but those standards are not in the regulation, and the regulation makes it clear that a browser cannot reject QWACS for other reasons not listed in the regulation.
Another example, Mozilla has found that CAs who simply request audits done to ETSI standards (the standards imposed by this regulation) will often end up with audits that are incomplete (unable to audit all relevant controls). This can happen for legitimate reasons, but the audit results don't provide enough details here, hence Mozilla added a requirement for an ETSI Audit Attestation Letter (AAL) that explains these limitations. Even worse, once the impediments are no longer in place, by often ETSI auditors do not re-audit the previously un-auditable controls for the last time period. Mozilla needed to impose additional rules including explaining what if any controls could not be audited, and also rules that the next audit must cover previously un-auditable controls for the previously issued audit, in addition to auditing for the that time period. Describing how to do this audits properly within in the ETSI context is complicated because the ETSI audit standards were not really designed to make such rules (Full audit of all controls over all timespans, re-auditing later if some controls could not be evaluated for any reason the first time) easy.