What evidence should a CA retain for subscriber agreements?
The evidence should prove the exact agreement, the terms accepted, the person or entity accepting, and the specific choices made during registration. ETSI EN 319 411-1 requires the agreement with the subscriber to be recorded, and, where the subscriber and subject are separate, the subject agreement to be recorded as well.
Records should also connect the agreement to the registration file. ETSI EN 319 411-1 lists the storage location of applications and identification documents, including the subscriber agreement, plus specific choices in the agreement such as consent to certificate publication.
- Retain the signed or electronically accepted subscriber agreement and the version of terms and conditions presented at acceptance.
- Keep evidence of the wilful act used for acceptance, such as signature data, acceptance timestamp, account identity, or equivalent trace record.
- Record publication consent, secure-cryptographic-device acceptance, certificate-information confirmation, and any other agreement choices that affect issuance or relying-party information.
- Retain the agreement records for the period indicated to the subscriber as part of the terms and conditions.
Requirements REG-6.3.4-07, REG-6.3.4-08, and REG-6.3.4-17 support recorded acceptance and retention of subscriber-agreement records.
Requirement REG-6.4.5-04 supports recording the storage location of applications and identification documents, including the subscriber agreement.