稽核結果之公開
Communication of results
The Audit Report SHALL state explicitly that it covers the relevant systems and processes used in the issuance of all Certificates that assert one or more of the policy identifiers listed in Section 7.1.6.1. The CA SHALL make the Audit Report publicly available.
稽核報告(Audit Report)應(SHALL)明確載明,其涵蓋所有宣告第 7.1.6.1 節所列一個或多個政策識別碼之憑證簽發所使用的相關系統及流程。憑證機構(Certification Authority,CA)應(SHALL)公開稽核報告。
The CA MUST make its Audit Report publicly available no later than three months after the end of the audit period. In the event of a delay greater than three months, the CA SHALL provide an explanatory letter signed by the Qualified Auditor.
CA 應(MUST)於稽核期間結束後 3 個月內公開其稽核報告。CA 若延遲超過 3 個月,應(SHALL)提供由合格稽核業者(Qualified Auditor)簽署之說明函。
The Audit Report MUST contain at least the following clearly-labelled information:
- name of the organization being audited;
- name and address of the organization performing the audit;
- the SHA-256 fingerprint of all Roots and Subordinate CA Certificates, including Cross-Certified Subordinate CA Certificates, that were in-scope of the audit;
- audit criteria, with version number(s), that were used to audit each of the certificates (and associated keys);
- a list of the CA policy documents, with version numbers, referenced during the audit;
- whether the audit assessed a period of time or a point in time;
- the start date and end date of the Audit Period, for those that cover a period of time;
- the point in time date, for those that are for a point in time;
- the date the report was issued, which will necessarily be after the end date or point in time date; and
- (for audits conducted in accordance with any of the ETSI standards) a statement to indicate if the audit was a full audit or a surveillance audit, and which portions of the criteria were applied and evaluated, e.g. DVCP, OVCP, NCP, NCP+, LCP, EVCP, EVCP+, QCP-w, Part 1 (General Requirements), and/or Part 2 (Requirements for Trust Service Providers).
- (for audits conducted in accordance with any of the ETSI standards) a statement to indicate that the auditor referenced the applicable CA/Browser Forum criteria, such as this document, and the version used.
稽核報告應(MUST)至少包含下列清楚標示之資訊:
- 被稽核組織之名稱;
- 執行稽核之組織名稱及地址;
- 稽核範圍內所有根憑證機構(Root CA)憑證及下屬憑證機構(Subordinate CA)憑證(包括交互認證之下屬憑證機構憑證)的 SHA-256 指紋;
- 用於稽核各憑證(及其相關金鑰)之稽核準則及其版本號;
- 稽核期間所引用之 CA 政策文件清單及其版本號;
- 稽核之評估期間類型為一段期間或特定時間點;
- 稽核涵蓋一段期間者,其稽核期間(Audit Period)之起訖日期;
- 稽核針對特定時間點者,該時間點之日期;
- 報告出具日期(該日期必然晚於稽核期間之結束日期或該時間點之日期);及
- (依任一 ETSI 標準進行稽核時)說明本次稽核為完整稽核或監督稽核,以及所適用及評估的準則內容,例如 DVCP、OVCP、NCP、NCP+、LCP、EVCP、EVCP+、QCP-w、第一部分(一般要求規定)及/或第二部分(信賴服務提供者要求規定)。
- (依任一 ETSI 標準進行稽核時)說明稽核者已引用適用之 CA/Browser Forum 準則(例如本文件),並載明所引用之版本。
An authoritative English language version of the publicly available audit information MUST be provided by the Qualified Auditor and the CA SHALL ensure it is publicly available.
公開稽核資訊應(MUST)由合格稽核業者(Qualified Auditor)提供具權威性之英文版本,且 CA 應(SHALL)確保該版本可公開取得。
The Audit Report MUST be available as a PDF, and SHALL be text searchable for all information required. Each SHA-256 fingerprint within the Audit Report MUST be uppercase letters and MUST NOT contain colons, spaces, or line feeds.
稽核報告應(MUST)以 PDF 格式提供,且其中所有必要資訊應(SHALL)均可用文字進行搜尋。稽核報告中的每一個 SHA-256 指紋應(MUST)使用大寫字母,且不得(MUST NOT)包含冒號、空格或換行字元。