CAcert Communication Policy (CCP)
Author: Sam Johnston
Creation date: 2008-04-16
Status: WIP 2008-04-16
Next status: DRAFT 2008-04-XX
0. Preliminaries
This CAcert policy describes how CAcert communicates as required for achieving its mission.
1. Scope
This policy is applicable to:
- Press Releases and Announcements
- Internet Email
- Internet Relay Chat (IRC)
2. Requirements
This section describes all CAcert communication channels.
-
Press Releases and Announcements
- Community Members MAY communicate on their areas, but these are considered community views.
- Targeted announcements MAY be sent to a minority subset of users who have opted-in to receiving information on the topic.
- Press releases and official announcements MUST be approved by the board and issued via:
- Digitally signed email to appropriate mailing list(s).
- Posting and indefinite archiving on the official CAcert web site(s)
-
Internet Email
-
Email Aliases are official email addresses within the CAcert domain(s) (eg john@cacert.org).
- All official CAcert communications MUST be conducted using an official address, which is typically a forwarding service.
- Access to full accounts (available only to officials listed on the organisation chart) SHALL be available via web interface and standard mail protocols.
- Outbound mail SHOULD contain the full name and short reference to the official capacity of the user: John Citizen (CAcert AO) <john@cacert.org>.
- Role accounts (eg support@cacert.org) SHALL be implemented as a mailing list or automated issue tracking system as appropriate.
-
Mailing Lists are automated distribution lists containing CAcert community members.
- List management (new list creation, dead list removal) SHALL be managed by the board.
- List membership SHALL be restricted to CAcert Community members and all posts are contributions, as described in the CCA.
- Lists SHALL follow the naming convention of cacert-<listname>@lists.cacert.org, with important lists (eg support, board) aliased @cacert.org
- List policy SHALL be set on a per-list basis (eg open/closed, searchable archives, etc.)
- Open lists (eg cacert-policy) shall be accessible by anyone (including Internet search engines) and closed lists (eg cacert-board) only by list members.
- Posting to discussion lists (eg cacert-policy) MUST be restricted to list members and MUST NOT be restricted for role lists (eg cacert-board).
- Messages which do not meet list policy (eg size, non-member) MUST be immediately rejected.
- Subscription requests MUST be confirmed by the requestor and subscriber lists MUST NOT be revealed..
- Web based archives SHALL be maintained and authentication MUST reflect list policy.
-
Automated Email is sent by various CAcert systems automatically
- All new automated emails MUST be approved by the board.
- Automated emails SHOULD only be sent in response to a user action.
-
Personal Email is individual personal addresses of CAcert Community members (eg john@gmail.com).
- Personal email MUST NOT be used for official CAcert purposes.
-
Internet Relay Chat (IRC)
- An IRC service SHALL be maintained at irc.cacert.org which SHALL be available via SSL.
3. Implementation
This section describes how CAcert communication channels are to be implemented.
-
General
- CAcert System Administrators SHALL have discretion as to the technical implementation of this policy and SHALL report status to the board periodically.
-
Security
- Authentication (where required) MUST be done via username and password and/or CAcert certificate.
- Transport encryption MUST be used where possible.
- Content encryption MAY be used where appropriate.
- All outbound mail SHOULD be digitally signed.
-
Internet Email
- All mails MUST be securely archived for a period of 10 years.
- All mails MUST be subject to appropriate spam prevention mechanisms (eg SpamAssassin, greylisting).
- All mails MUST be subject to appropriate virus and content filtering (eg ClamAV, content types).
4. Acceptable Usage Policy
CAcert infrastrucutre is for official, lawful, non-commercial, non-abusive CAcert use only.