diff --git a/Agreements/3PVDisclaimerAndLicence.html b/Agreements/3PVDisclaimerAndLicence.html index d1e281d..1195b37 100644 --- a/Agreements/3PVDisclaimerAndLicence.html +++ b/Agreements/3PVDisclaimerAndLicence.html @@ -10,64 +10,41 @@
-This is wip-V0.03. +This is wip-V0.05 as of 20091213.
-++0. Preamble
-0.2 Background
++This section is not part of the licence but may be explanatory. +Skip to licence. +
Being that,
- - CAcert is a Certificate Authority ("the CA"), + CAcert is a Certification Authority ("the CA"),
- the CA offers a free certificate service to its subscribers,
- for the direct benefit and RELIANCE of its Community of signed-up users ("Members"), + RELIANCE being defined as the Member's act in making a decision, + including taking a risk, in whole or in part based on the certificate, + and
- where possible, of some indirect benefit and USE to other general users - ("end-users") of the Internet; + ("end-users") of the Internet, + where USE is defined as allowing a certificate to + participate in a protocol, as decided and facilitated + by the user's software, with no significant input or + knowledge being required of the user;
@@ -103,10 +80,10 @@ And that, in offering the USE of certificates to the end-user, direct relationship,
by way of an open, indirect offering, - the CA provides its + the CA offers its Non-Related Persons -- Disclaimer and Licence - for the end-user ("NRP"), in which + to the end-user ("NRP"), in which +
- the CA disclaims liability to NRPs,
- @@ -114,6 +91,9 @@ And that, in offering the USE of certificates to the end-user,
- the CA specifically does not permit the NRPs to RELY,
+ and that NRPs have a choice of joining the Community + and thus becoming a Member (which overrides the NRP-DaL); @@ -134,6 +114,9 @@ And that, the Vendor has the primary and only direct relationship with the end-user,
the Vendor chooses not to be a Member of CAcert, + + and therefore Vendor needs a Licence to distribute the roots + to its end-users; @@ -156,39 +139,26 @@ We both, CA and Vendor, agree that, -
0.2 Parties
- -With the above understanding, the following Licence and Disclaimer is offered -by CA to Vendor. - -0.3 Terms
--RELIANCE. - A Member's act in making a decision, - including taking a risk, - in whole or in part based on the certificate. -
--USE. - The event of allowing a certificate to participate - in a protocol, as decided and facilitated by the user's software. - In general, no significant input is required of the user. +With the above understanding, +the following Licence and Disclaimer is offered by CAcert to Vendor.
--Other terms used in this agreement are as defined in the - -CAcert Community Agreement. -
+
+
+1. Agreement and Licence1.1 Agreement-You and CAcert both agree to the terms and conditions in this agreement. +We (the Vendor and the CA) +both agree to the terms and conditions in this agreement. The relationship between the CA and the Vendor is based on this agreement. Your agreement is given by your distribution of the root within your distribution of your root list. @@ -197,7 +167,8 @@ distribution of your root list. 1.2 Other Agreements-The relationship between the Vendor and the end-user is based on Vendor's own agreement +The relationship between the Vendor and the end-user +is based on Vendor's own agreement ("end-user licence agreement" or EULA). Generally, the Vendor offers the EULA to the end-user in the act of distributing the software and roots. @@ -220,57 +191,34 @@ CA offers this licence to permit Vendor to distribute CA's roots within Vendor's root list to Vendor's end-users. -1.4 Agreement in Spirit+1.4 Vendor's Agreement with End-User-Vendor agrees to make its relationship to end-users -compatible and aligned with the CA's NRP-DaL. -Specifically, the Vendor must: +Vendor agrees -
-all with respect to the root list -(including root keys, certificates, -and related cryptographic and security software). - - -1.5 Agreement in Practice- --Where agreement is explicitly sought from the end-user, -they may be offered and agree to: - - -
-Vendors are encouraged to ship the NRP-DaL with their software,
-and make available means for the end-user to further
-examine the NRP-DaL.
- 1.6 Fair and Non-Discriminatory+1.5 Fair and Non-Discriminatory
Vendor agrees to make available CA's root key
in a fair and non-discriminatory way to Vendor's end-users.
- +In accordance with the general principles of PKI +and the fact that the CA makes statements of interest +within certificates, the Vendor is strongly encouraged +to reasonably represent to the end-user +that the CA is the issuer of the certificate +and the maker of claims within the certificate. +The extent to which the end-user is aware that the +CA is the person making claims is likely to be +material in a dispute over claims. 2. Disclaimer@@ -281,11 +229,14 @@ in a fair and non-discriminatory way to Vendor's end-users. Vendor's relationship with end-users creates risks, liabilities and obligations due to the end-user's permitted USE of the certificates, and potentially through other activities such as inappropriate -and unpermitted RELIANCE. +and non-permitted RELIANCE.-We in general DISCLAIM ALL LIABILITY to each other and to the end-user. +We in general DISCLAIM ALL LIABILITY to each other. +Vendor acknowledges and confirms that +the CA disclaims all liability to the end-user +in NRP-DaL. @@ -293,28 +244,19 @@ We in general DISCLAIM ALL LIABILITY to each other and to the end-user.Notwithstanding the general disclaimer on liability above, -we agree that, to the extent that CAcert is reasonably -represented to the Vendor's end-user by the software -as being the Certificate Authority, at the events and -circumstances of question, -liability of CAcert is strictly limited to be 1000 euros. +we agree that, +liability of Vendor and of the CA is strictly limited to be 1000 euros. This is the same limit of liability that applies to each member of the CAcert Community. --To the extent that the CA is not reasonably represented -to the end-user, we agree that any liability is limited -to the lowest of agreed liabilities of all CAs for all -roots shipped by the Vendor, and 1000 euros. - -3. Legal Matters3.1 LawThe Choice of Law is that of NSW, Australia. +Policies in force within CAcert are incorporated. 3.2 Dispute Resolution@@ -322,41 +264,18 @@ The Choice of Law is that of NSW, Australia.We agree that all disputes arising out of or in connection to this agreement -and the root key of the CA +and the root and certificates of the CA shall be referred to and finally resolved by Arbitration under the Dispute Resolution Policy of the CA -(DRP => COD7). +(COD7). The ruling of the Arbitrator is binding and final on CA and Vendor alike. --We further agree, as a single exception to DRP, -that the single Arbitrator may be chosen from outside -the CAcert Community. - + |
-The CA also offers a CAcert Community Agreement (CCA). -The CCA replaces the NRP-DaL and this present agreement -for those parties that accept it. -
- --If a Community member is also an end-user, then the provisions -of the CCA will replace all elements of the CA's NRP-DaL, -and will dominate this present agreement. -
- --Acceptance alone of this present agreement by the Vendor -does not imply that Vendor is a Community User/Member. -
- -+ + +The following parts are not part of the above licence, @@ -422,3 +341,22 @@ random users would have "got it" when presented with the same information, however this is not quite how it is tested in law; instead, it is more of a gut-feeling.
+ +Z.3 Recursive Distribution
+ ++This licence is not intended to limit the ability of +a re-distributor of Vendor's root list from operating under +the same conditions as the Vendor. The licence applies +equally to all distributors of CA's roots. +It is the re-distributor's responsibility +to be aware of this licence and to take appropriate +steps. The primary Vendor discharges any responsibility +to the re-distributor by making available this licence +on the same basis as its other licences. +
+ +