Re: ODP: Re: ODP: Re: KIR S.A. Root Inclusion Request

2014-09-30 Thread Matt Palmer
On Tue, Sep 30, 2014 at 01:17:22PM +0200, Certificates wrote: We are able to add some additional information to our CPS. In our opinion they should be more general than those in our explanations sent to you. More detailed information are placed in our internal procedures, which are checked

Re: ODP: Re: ODP: Re: KIR S.A. Root Inclusion Request

2014-09-30 Thread Kathleen Wilson
On 9/30/14, 1:40 PM, Matt Palmer wrote: The CPS is a Certification *Practice* Statement, not a Certification *Principles* Statement, and so I think it is reasonable to expect a description of the practices undertaken in issuing certificates. Matt is correct. BR section 8.2.1 says: The CA

ODP: Re: KIR S.A. Root Inclusion Request

2014-09-29 Thread Certificates
On Fri, Sep 26, 2014 at 02:42:05PM +0200, Certificates wrote: I don't read the CP (specifically, s2.4) as confirming that the Applicant controls the Fully-Qualified Domain Name (as per BR 1.1.9 s.9.2.1). KIR's answer: To get a SSL certificate client has to provide(CSP s.3.2): That's

ODP: RE: KIR S.A. Root Inclusion Request

2014-09-29 Thread Certificates
For the domain name specified in the order we check at http://www.dns.pl/cgi-bin/whois.pl whether the data presented to the domain owner are the same as customer data and the data for the certificate indicated in the order and agreement. If they are the same operator asks the administrator of

Re: ODP: Re: KIR S.A. Root Inclusion Request

2014-09-29 Thread Matt Palmer
On Mon, Sep 29, 2014 at 03:41:07PM +0200, Certificates wrote: On Fri, Sep 26, 2014 at 02:42:05PM +0200, Certificates wrote: -agreement, -order, -document confirming rights to the domain . What valid forms can this document take? What steps are taken to verify or validate that