added TrustedThirdParty (TTP) policy WIP

git-svn-id: http://svn.cacert.org/CAcert/Policies@776 14b1bab8-4ef6-0310-b690-991c95c89dfd
This commit is contained in:
Sam Johnston 2008-04-22 18:45:46 +00:00
parent ded7dd9eba
commit 9a0fbd6897

199
TrustedThirdParty.html Normal file
View file

@ -0,0 +1,199 @@
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>
CACert Trusted Third Party (TTP) Policy
</title>
</head>
<body>
<h1>
CACert Trusted Third Party (TTP) Policy
</h1>
<p>
<a href="../PolicyOnPolicy.html"><img src="../Images/cacert-wip.png" alt="CAcert Policy Status" height="31" width="88" style="border-style: none;" /></a><br />
Author: Sam Johnston<br />
Creation date: 2008-04-22<br />
Status: WIP 2008-04-22<br />
Next status: DRAFT 05-2008<br />
<!-- $Id$ -->
</p>
<h2>
0. Preliminaries
</h2>
<p>
This CAcert sub-policy extends the Assurance Policy ("AP") by specifying how the CAcert Assurance Program ("CAP") is to be remotely conducted for entities where insufficient local assurer(s) are available. An existing local CAcert Assurer shall be assigned to conduct the assurance to their satisfaction using TWO Trusted Third Parties ("TTP"s) under the supervision of the Assurance Officer ("AO").
</p>
<p>
Successful completion of the Trusted Third Party process shall result in the Assuree achieving the status of Assurer (eg the allocation of sufficient points to reach 100).
</p>
<h2>
1. Scope
</h2>
<p>
This sub-policy is restricted to entities where insufficient local assurer(s) are available to reach Assurer status by the usual means within a 30 day period.
</p>
<h2>
2. Requirements
</h2>
<h3>
2.1 Trusted Third Party (TTP)
</h3>
<p>
Each of the TWO Trusted Third Party(s) ("TTP"):
</p>
<ol style="list-style-type: lower-alpha;">
<li>MUST be <i><strong>verifiably</strong></i> one of the following:<br />
<ol style="list-style-type: lower-roman;">
<li>
<strong>Accountant</strong> licensed and/or certified by the local authority (eg CPA)
</li>
<li>
<strong>Bank Manager</strong> of a branch of a banking institution
</li>
<li>
<strong>Justice of the Peace</strong> duly and verifiably elected or appointed
</li>
<li>
<strong>Lawyer</strong> currently practicing and registered with the bar association or equivalent
</li>
<li>
<strong>Notary Public</strong> authorised to authenticate documents in their jurisdiction
</li>
</ol>
</li>
<li>MUST retain the TTP form for at least 60 days and respond to CAcert enquiries in a timely fashion
</li>
<li>SHOULD have experience with the CAcert TTP program, unless no experienced local TTPs are available within a 30 day period
</li>
</ol>
<h3>
2.2 Assurer
</h3>
<p>
An assurer conducting a remote assurance using TTPs:
</p>
<ol style="list-style-type: lower-alpha;">
<li>MUST be satisfied as to the identity and competency of the TTP, as though they were to be conducting the assurance themselves
</li>
<li>SHOULD have experience with the TTP program, unless no experienced local Assurers are available within a 30 day period
</li>
<li>SHOULD recommend TTPs to the Assuree where possible so as to improve security
</li>
<li>MAY charge a reasonable fee for the service, provided that fee is disclosed in advance
</li>
</ol>
<h3>
2.3 Assuree
</h3>
<p>
An assuree being assured using the CAcert TTP program:
</p>
<ol style="list-style-type: lower-alpha;">
<li>MUST agree to be bound the CAcert Community Agreement (CCA), including the Disupute Resolution Policy (DRP)
</li>
<li>MUST justify to the Assurer as to why it is the standard processes are not appropriate
</li>
<li>MUST provide adequate identification to satisfy the prevailing CAcert Assurance Policy and the TTP
</li>
<li>MUST cover the costs of their assurance (if any), including fees imposed by TTPs and Assurers
</li>
</ol>
<h2>
3. Processes
</h2>
<h3>
3.1 Assurance
</h3>
<ol style="list-style-type: lower-alpha;">
<li>Assuree SHALL create a CAcert account and agree to the CAcert Community Agreement (CCA)
</li>
<li>Assuree SHOULD first attempt to use the usual means for assurance
</li>
<li>Assuree SHOULD contact the most local and most (TTP) experienced Assurer available
</li>
<li>Assurer SHOULD refer Assuree to the most known, experienced and appropriate TTPs in preference to:<br />
<ol style="list-style-type: lower-roman;">
<li>unknown, inexperienced or inappropriate TTPs
</li>
<li>TTPs proposed by the Assuree
</li>
</ol>
</li>
<li>Assuree SHALL have their identity verified by the TTP by:<br />
<ol style="list-style-type: lower-roman;">
<li>obtaining and printing two copies of the CAcert TTP form
</li>
<li>taking two copies of any identity documents to be presented to the TTP
</li>
<li>meeting with the TTP in person and furnishing <strong>at least</strong> sufficient identification to meet the requirements of the prevailing Assurance Policy
</li>
<li>executing the CAcert TTP form in dupicate, in the presence of the TTP
</li>
<li>leaving one TTP form and copies of identity documents with the TTP for at least 60 days
</li>
<li>sending one TTP form and copies of identity documents to the Assurer by mutually agreed medium (eg post or encrypted email)
</li>
</ol>
</li>
<li>Assurer MUST authenticate the TTP to their satisfaction by:<br />
<ol style="list-style-type: lower-roman;">
<li>searching for their details in an appropriate, official public registry (eg government site, association registry)
</li>
<li>contacting the TTP using these details to verify their identity
</li>
<li>verifying that the TTP is suitable in terms of meeting the requirements of this policy
</li>
<li>verifying that the meeting did indeed take place and that the Assuree was adequately identified
</li>
</ol>
</li>
<li>Assurer MUST submit their reports for BOTH TTPs to the AO within 30 days of the date of each TTP meeting
</li>
<li>Assurer MUST securely destroy all copies held no less than 60 days and no more than 90 days from the date of the TTP meeting
</li>
<li>Disputes requiring access to the TTP form and copies of identity documents must be handled within 60 days of the TTP meeting (after which time the TTP MAY be revoked)
</li>
</ol>
<h2>
4. Exclusions
</h2>
<p>
The following exclusions (with reasoning) apply to the TTP program:
</p>
<ol style="list-style-type: lower-alpha;">
<li>
<strong>Countries:</strong><br />
<ol style="list-style-type: lower-roman;">
<li>None
</li>
</ol>
</li>
<li>
<strong>Trusted Third Parties:</strong><br />
<ol style="list-style-type: lower-roman;">
<li>Unqualified TTPs (due to inadequate qualifications, eg students)
</li>
</ol>
</li>
<li>
<strong>Assurers:</strong><br />
<ol style="list-style-type: lower-roman;">
<li>Underage assurers (due to inadequate experience/liability)
</li>
</ol>
</li>
<li>
<strong>Assurees:</strong><br />
<ol style="list-style-type: lower-roman;">
<li>Existing CAcert Assurers (due to lack of demonstrable need)
</li>
</ol>
</li>
</ol>
<p>
<a href="http://validator.w3.org/check?uri=referer"><img src="../Images/valid-xhtml11-blue" alt="Valid XHTML 1.1" height="31" width="88" style="border-style: none;" /></a>
</p>
</body>
</html>