<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">ANF Autoridad de Certificación votes
yes.<br>
<div class="moz-signature">
<p><img src="cid:part1.00010407.07010601@anf.es" alt="ANF
Autoridad de Certificación"></p>
<b>Enric Castillo</b><br>
Departamento de Ingeniería<br>
ANF Autoridad de Certificación<br>
<a style="color: #007fa9;" href="mailto:enric.castillo@anf.es">enric.castillo@anf.es</a><br>
<a style="color: #007fa9;" href="https://www.anf.es">www.anf.es</a><br>
<br>
<b>Aviso</b>
<p style="font-size: x-small;">Este mensaje se dirige
exclusivamente a su destinatario y puede contener información
privilegiada o confidencial y/o datos de carácter personal,
cuya difusión está regulada por la Ley Orgánica de Protección
de Datos y la Ley de Servicios de la Sociedad de la
Información. Si usted no es el destinatario indicado (o el
responsable de la entrega al mismo), no debe copiar o entregar
este mensaje a terceros bajo ningún concepto. Si ha recibido
este mensaje por
error o lo ha conseguido por otros medios, le rogamos que nos
lo comunique inmediatamente por esta misma vía y proceda a su
eliminación irreversible. Las opiniones,
conclusiones y demás informaciones incluidas en este mensaje
que no estén relacionadas con asuntos profesionales de ANF
Autoridad de Certificación no están respaldadas por la
empresa.
</p>
</div>
El 31/12/2013 0:47, Ben Wilson escribió:<br>
</div>
<blockquote cite="mid:2efa01cf05b9$73d10300$5b730900$@digicert.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal">Ballot 113 - Revision to QIIS in EV
Guidelines <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The following proposal comes from EV
working group. Jeremy Rowley made the following motion, and
Rich Smith and Kirk Hall have endorsed it. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This ballot proposes a replacement to
Section 11.10.5 of the Extended Validation Guidelines, which
defines the qualifications of a QIIS. The previous QIIS
definition did not accurately capture current CA practices. In
fact, a strict reading of the existing definition might imply
that CAs were prohibited from using Dun & Bradstreet,
Hoovers, and other commercially reliable sources generally
regarded as accurate sources of information. The proposed
definition consolidates confusing and overlapping requirements
while clarifying the QIIS verification requirements for CAs.
The new definition permits CAs to use databases of information
if the CA has documented its process to verify the data’s
accuracy and the CA knows the information is not
self-reported. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--- Motion begins ---<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Effective immediately:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Replace Section 11.10.5 in the EV
Guidelines:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">11.10.5 Qualified Independent Information
Source<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">A Qualified Independent Information Source
(QIIS) is a regularly-updated and current, publicly available,
database designed for the purpose of accurately providing the
information for which it is consulted, and which is generally
recognized as a dependable source of such information. A
commercial database is a QIIS if the following are true:<o:p></o:p></p>
<p class="MsoNormal">(1) Industry groups rely on the
database for providing accurate location or contact
information;<o:p></o:p></p>
<p class="MsoNormal">(2) The database distinguishes
between self-reported data and data reported by independent
information sources;<o:p></o:p></p>
<p class="MsoNormal">(3) The database provider
identifies how frequently they update the information in their
database;<o:p></o:p></p>
<p class="MsoNormal">(4) Changes in the data that will
be relied upon will be reflected in the database in no more
than 12 months; and<o:p></o:p></p>
<p class="MsoNormal">(5) The database provider uses
authoritative sources independent of the Subject, or multiple
corroborated sources, to which the data pertains. <o:p></o:p></p>
<p class="MsoNormal">Databases in which the CA or its owners or
affiliated companies maintain a controlling interest, or in
which any Registration Authorities or subcontractors to whom
the CA has outsourced any portion of the vetting process (or
their owners or affiliated companies) maintain any ownership
or beneficial interest do not qualify as a QIIS. The CA MUST
check the accuracy of the database and ensure its data is
acceptable.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">With the following proposed language for
Section 11.10.5:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">11.10.5 Qualified Independent Information
Source<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">A Qualified Independent Information Source
(QIIS) is a regularly updated and publicly available database
that is generally recognized as a dependable and accurate
source for certain information. <o:p></o:p></p>
<p class="MsoNormal">A database qualifies as a QIIS if the CA
determines that: <o:p></o:p></p>
<p class="MsoNormal">(1) Industries other than the certificate
industry rely on the database for accurate location, contact,
or other information; and<o:p></o:p></p>
<p class="MsoNormal">(2) The database provider updates its data
on at least an annual basis.<o:p></o:p></p>
<p class="MsoNormal">The CA SHALL use a documented process to
check the accuracy of the database and ensure its data is
acceptable, including reviewing the database provider’s terms
of use. <o:p></o:p></p>
<p class="MsoNormal">The CA SHALL NOT use any data in a QIIS
that the CA knows is (i) self-reported and (ii) not verified
by the QIIS as accurate. <o:p></o:p></p>
<p class="MsoNormal">Databases in which the CA or its owners or
affiliated companies maintain a controlling interest, or in
which any Registration Authorities or subcontractors to whom
the CA has outsourced any portion of the vetting process (or
their owners or affiliated companies) maintain any ownership
or beneficial interest, do not qualify as a QIIS. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--- Motion ends ---<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The review period for this ballot shall
commence immediately at 2300 UTC on 30 December 2013 and will
close on 6 January 2014. <o:p></o:p></p>
<p class="MsoNormal">Unless the motion is withdrawn during the
review period, the voting period will start immediately
thereafter and will close at 2300 UTC on 13 January 2014. <o:p></o:p></p>
<p class="MsoNormal">Votes must be cast by posting an on-list
reply to this thread.<o:p></o:p></p>
<p class="MsoNormal">A vote in favor of the ballot must indicate
a clear ‘yes’ in the response.<o:p></o:p></p>
<p class="MsoNormal">A vote against the ballot must indicate a
clear ‘no’ in the response.<o:p></o:p></p>
<p class="MsoNormal">A vote to abstain must indicate a clear
‘abstain’ in the response.<o:p></o:p></p>
<p class="MsoNormal">Unclear responses will not be counted.<o:p></o:p></p>
<p class="MsoNormal">The latest vote received from any
representative of a voting member before the close of the
voting period will be counted.<o:p></o:p></p>
<p class="MsoNormal">Voting members are listed here:
<a class="moz-txt-link-freetext" href="https://cabforum.org/members/">https://cabforum.org/members/</a><o:p></o:p></p>
<p class="MsoNormal">In order for the motion to be adopted, two
thirds or more of the votes cast by members in the CA category
and more than one half of the votes cast by members in the
browser category must be in favor. <o:p></o:p></p>
<p class="MsoNormal">Quorum is currently six (6) members– at
least six members must participate in the ballot, either by
voting in favor, voting against, or by abstaining for the vote
to be valid.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Public mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Public@cabforum.org">Public@cabforum.org</a>
<a class="moz-txt-link-freetext" href="https://cabforum.org/mailman/listinfo/public">https://cabforum.org/mailman/listinfo/public</a>
</pre>
</blockquote>
<br>
</body>
</html>