Skip to content

Latest commit

 

History

History
40 lines (30 loc) · 1.75 KB

File metadata and controls

40 lines (30 loc) · 1.75 KB

Example PR: Update Audit Requirements (filled)

Title: REQ: Update Section 4.1 Audit Requirements — require explicit WebTrust attestation for server authentication EKU

Summary

  • Updated Requirements.md Section 4.1 to require explicit WebTrust attestation language for server authentication EKU.

Rationale

  • Aligns Microsoft Audit Requirements with recent clarifications in EN 319 411-2 and ensures consistency with CCADB automation parsing requirements.

Changes

  • Requirements.md: Section 4.1 — added clause that specifies the required attestation wording and upload process.
  • Changelog.md: appended a row proposing the change.

References

Changelog entry

| 1.1 | 2025-12-22 | Updated Audit Requirements in Section 4.1 to require WebTrust attestation for server authentication EKU |

Program reviewers & sign-off

  • Added msroot@microsoft.com as a reviewer and requested explicit sign-off.

Compliance checklist

  • This change affects Audit Requirements; WebTrust selected
  • Proposed attestation wording included in the PR body
  • CCADB actions documented in related issue #456 (example)
  • Timelines added and owner named
  • Audit submission issue opened: #456

Checklist

  • Updated Requirements.md with the final wording and section number(s)
  • Added or updated Changelog.md with version, date, and short summary
  • Provided a short rationale and authoritative reference link(s) in the PR body
  • Marked Program-team reviewers and requested msroot@microsoft.com sign-off
  • Verified Markdown renders correctly (preview) and tables align

This PR is an example to demonstrate the expected fields and approach for audit-related changes.