From b34de467a5ac90a604492a2ce233add4df68b9eb Mon Sep 17 00:00:00 2001 From: Sam Johnston Date: Wed, 23 Apr 2008 13:44:32 +0000 Subject: [PATCH] fixes per discussion git-svn-id: http://svn.cacert.org/CAcert/Policies@783 14b1bab8-4ef6-0310-b690-991c95c89dfd --- TrustedThirdParty.html | 51 ++++++++++++++++++++++++++++-------------- 1 file changed, 34 insertions(+), 17 deletions(-) diff --git a/TrustedThirdParty.html b/TrustedThirdParty.html index 1e60cb8..41c0502 100644 --- a/TrustedThirdParty.html +++ b/TrustedThirdParty.html @@ -4,12 +4,12 @@ - CACert Trusted Third Party (TTP) Policy + CACert Remote Assurance Policy (RAP)

- CACert Trusted Third Party (TTP) Policy + CACert Remote Assurance Policy (RAP)

CAcert Policy Status
@@ -23,10 +23,10 @@ 0. Preliminaries

- This CAcert sub-policy extends the Assurance Policy ("AP") by specifying how the CAcert Assurance Program ("CAP") is to be remotely conducted for members where insufficient local assurer(s) are available. An existing local CAcert Assurer shall be assigned to conduct the assurance to their satisfaction using TWO Trusted Third Parties ("TTP"s) under the supervision of the Assurance Officer ("AO"). + This CAcert sub-policy extends the Assurance Policy ("AP") by specifying how assurances are to be remotely conducted for members where insufficient assurer(s) are available. A Remote Assurer ("RA") shall be assigned by a board-appointed Remote Assurance Officer ("RAO") to conduct the assurance to their satisfaction using TWO Trusted Third Parties ("TTP"s).

- Successful completion of the Trusted Third Party process shall result in the Assuree achieving the status of Assurer (eg the allocation of sufficient points to reach 100). However this status should not be considered permanent as points may expire so they should seek assurance by the usual means as soon as practicable. + Successful completion of the process shall result in the Assuree achieving the status of Assurer (eg the allocation of sufficient points to reach 100). However this status should not be considered permanent and the Assuree must seek assurance by the usual means as soon as practicable.

1. Scope @@ -38,13 +38,13 @@ 2. Requirements

- 2.1 Trusted Third Party (TTP) + 2.1 Trusted Third Party ("TTP")

- Each of the TWO Trusted Third Party(s) ("TTP"): + Each of the TWO TTPs:

    -
  1. MUST be verifiably one of the following:
    +
  2. MUST be verifiably practicing identification procedures, typically one of the following:
    1. Accountant licensed and/or certified by the local authority (eg CPA) @@ -66,26 +66,28 @@
  3. -
  4. MUST retain the TTP form for at least 60 days and respond to CAcert enquiries in a timely fashion +
  5. MUST retain the TTP form(s) for at least 60 days and respond to CAcert enquiries in a timely fashion
  6. SHOULD have experience with the CAcert TTP program, unless no experienced local TTPs are available within a 30 day period
  7. +
  8. SHOULD be recommended to the Assuree by the RA where possible so as to improve security +

- 2.2 Assurer + 2.2 Remote Assurer ("RA")

- An assurer conducting a remote assurance using TTPs: + An RA conducting assurances remotely using TTPs:

    -
  1. MUST be satisfied as to the identity and competency of the TTP, as though they were to be conducting the assurance themselves +
  2. MUST be approved by a board-appointed Remote Assurance Officer ("RAO")
  3. -
  4. SHOULD be the most senior assurer available +
  5. MUST be satisfied as to the identity and competency of the TTP in identification procedures, as though they were to be conducting the assurance themselves +
  6. +
  7. SHOULD be the most senior Assurer available
  8. SHOULD have experience with the TTP program, unless no experienced local Assurers are available within a 30 day period
  9. -
  10. SHOULD recommend TTPs to the Assuree where possible so as to improve security -
  11. MAY charge a reasonable fee for the service, provided that fee is disclosed in advance
@@ -161,6 +163,21 @@
  • Disputes requiring access to the TTP form and copies of identity documents must be handled within 60 days of the TTP meeting (after which time the TTP MAY be revoked)
  • +

    + 3. Documentation +

    +

    + 3.1 Remote Assurance Form +

    +

    + The Remote Assurance Form is to be completed (in duplicate for paper forms) and: +

    +
      +
    1. SHALL include all information required by the Assurance Policy +
    2. +
    3. SHOULD include a concise guide for Assurees and TTPs +
    4. +

    4. Exclusions

    @@ -178,14 +195,14 @@
  • Trusted Third Parties:
      -
    1. Unqualified TTPs (due to inadequate qualifications, eg students) +
    2. Unqualified TTPs (due to insufficient qualifications)
  • - Assurers:
    + Remote Assurers:
      -
    1. Underage assurers (due to inadequate experience/liability) +
    2. Assurers under age of majority (due to inadequate experience/liability)