Example: air traffic controller

CA/Browser Forum Baseline Requirements for the …

Forum Guideline i CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, Adopted on 22 Nov. 2011 with an Effective Date of 1 July 2012 Copyright 2011, The CA / Browser Forum , all rights reserved. Verbatim copying and distribution of this entire document is permitted in any medium without royalty, provided this notice is preserved. Upon request, the CA / Browser Forum may grant permission to make a translation of this document into a language other than English. In such circumstance, copyright in the translation remains with the CA / Browser Forum . In the event that a discrepancy arises between interpretations of a translated version and the original English version, the original English version shall govern. A translated version of the document must prominently display the following statement in the language of the translation:- 'Copyright 2011 The CA / Browser Forum , all rights reserved.

Jul 01, 2012 · Forum Guideline CA / Browser Forum Baseline Requirements, v. 1.0 1 1. Scope The Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates describe a subset of

Tags:

  Requirements, Baseline, Baseline requirements

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of CA/Browser Forum Baseline Requirements for the …

1 Forum Guideline i CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, Adopted on 22 Nov. 2011 with an Effective Date of 1 July 2012 Copyright 2011, The CA / Browser Forum , all rights reserved. Verbatim copying and distribution of this entire document is permitted in any medium without royalty, provided this notice is preserved. Upon request, the CA / Browser Forum may grant permission to make a translation of this document into a language other than English. In such circumstance, copyright in the translation remains with the CA / Browser Forum . In the event that a discrepancy arises between interpretations of a translated version and the original English version, the original English version shall govern. A translated version of the document must prominently display the following statement in the language of the translation:- 'Copyright 2011 The CA / Browser Forum , all rights reserved.

2 This document is a translation of the original English version. In the event that a discrepancy arises between interpretations of this version and the original English version, the original English version shall govern.' A request to make a translated version of this document should be submitted to Forum Guideline ii Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, v. Version , as adopted by the CA/Browser Forum on 22 Nov. 2011 with an Effective Date of 1 July 2012. These Baseline Requirements describe an integrated set of technologies, protocols, identity-proofing, lifecycle management, and auditing Requirements that are necessary (but not sufficient) for the issuance and management of Publicly-Trusted Certificates; Certificates that are trusted by virtue of the fact that their corresponding Root Certificate is distributed in widely-available application software.

3 The Requirements are not mandatory for Certification Authorities unless and until they become adopted and enforced by relying party Application Software Suppliers. Notice to Readers This version of the Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates present criteria established by the CA/Browser Forum for use by Certification Authorities when issuing, maintaining, and revoking publicly-trusted Certificates. The Requirements may be revised from time to time, as appropriate, in accordance with procedures adopted by the CA/Browser Forum . Because one of the primary beneficiaries of these Requirements is the end user, the Forum openly invites anyone to make recommendations and suggestions by email to the CA/Browser Forum at The Forum members value all input, regardless of source, and will seriously consider all such input.

4 The CA/Browser Forum The CA/Browser Forum is a voluntary organization of Certification Authorities and suppliers of Internet browser and other relying-party software applications. Membership as of November 2011 is as follows: Certification Authorities A-Trust GmbH AC Camerfirma SA Buypass AS Certum Comodo CA Ltd Cybertrust D-TRUST GmbH DanID A/S DigiCert, Inc. Digidentity BV Echoworx Corporation Entrust, Inc. GeoTrust, Inc. Getronics PinkRoccade GlobalSign , Inc. IdenTrust, Inc. ipsCA, IPS Certification Authority Izenpe Japan Certification Services, Inc. Kamu Sertifikasyon Merkezi Keynectis Logius PKIoverheid Network Solutions, LLC QuoVadis Ltd. RSA Security, Inc. SECOM Trust Systems CO., Ltd. Skaitmeninio sertifikavimo centras (SSC) StartCom Certification Authority SwissSign AG Symantec Corporation T-Systems Enterprise Services GmbH.

5 TC TrustCenter GmbH Thawte, Inc. T RKTRUST Trustis Limited Trustwave TWCA Verizon Wells Fargo Bank, Relying-Party Application Software Suppliers Apple Google Inc. KDE Microsoft Corporation Opera Software ASA Research in Motion Limited The Mozilla Foundation Other groups that have participated in the development of these Requirements include the AICPA/CICA WebTrust for Certification Authorities task force and ETSI ESI. Participation by such groups does not imply their endorsement, recommendation, or approval of the final Guideline ii TABLE OF CONTENTS 1. Scope .. 1 2. Purpose .. 1 3. References .. 1 4. Definitions .. 2 5. Abbreviations and Acronyms .. 5 6. Conventions .. 5 7. Certificate Warranties and Representations .. 6 By the CA .. 6 Certificate Beneficiaries .. 6 Certificate Warranties .. 6 By the Applicant .. 7 8. Community and Applicability .. 7 Compliance .. 7 Certificate Policies.

6 7 Implementation .. 7 Disclosure .. 7 Commitment to Comply .. 7 Trust model .. 8 9. Certificate Content and Profile .. 8 Issuer Information .. 8 Issuer Common Name Field .. 8 Issuer Domain Component Field .. 8 Issuer Organization Name Field .. 8 Issuer Country Name Field .. 8 Subject Information .. 8 Subject Alternative Name Extension .. 9 Subject Common Name Field .. 9 Subject Domain Component Field .. 9 Subject Organization Name Field .. 9 Subject Country Name Field .. 10 Other Subject Attributes .. 10 Certificate Policy Identification .. 10 Reserved Certificate Policy Identifiers .. 10 Root CA Certificates .. 11 Subordinate CA Certificates .. 11 Subscriber Certificates .. 11 Validity Period .. 11 Subscriber Public Key .. 11 Certificate Serial Number .. 12 Additional Technical Requirements .. 12 10. Certificate Application .. 12 Documentation Requirements .. 12 Certificate Request.

7 12 General .. 12 Request and Certification .. 12 Information Requirements .. 12 Subscriber Private Key .. 12 Subscriber and Terms of Use Agreement .. 13 General .. 13 Agreement Requirements .. 13 11. Verification Practices .. 14 Authorization by Domain Name Registrant .. 14 Verification of Subject Identity Information .. 14 Identity .. 15 Forum Guideline iii DBA/Tradename .. 15 Authenticity of Certificate Request .. 15 Verification of Individual Applicant .. 15 Verification of Country .. 16 Age of Certificate Data .. 16 Denied List .. 16 High Risk Requests .. 16 Data Source Accuracy .. 16 12. Certificate Issuance by a Root CA .. 16 13. Certificate Revocation and Status Checking .. 17 Revocation .. 17 Revocation Request .. 17 Certificate Problem Reporting .. 17 Investigation .. 17 Response .. 18 Reasons for Revocation .. 18 Certificate Status Checking .. 18 Mechanisms .. 18 Repository.

8 19 Response Time .. 19 Deletion of Entries .. 19 OCSP Signing .. 19 14. Employees and Third Parties .. 19 Trustworthiness and Competence .. 19 Identity and Background Verification .. 19 Training and Skill Level .. 20 Delegation of Functions .. 20 General .. 20 Compliance Obligation .. 20 Allocation of Liability .. 20 Enterprise RAs .. 20 15. Data Records .. 21 Documentation and Event Logging .. 21 Events and Actions .. 21 Retention .. 22 Audit Log Retention .. 22 Documentation Retention .. 22 16. Data Security .. 22 Objectives .. 22 Risk Assessment .. 22 Security Plan .. 22 Business Continuity .. 22 System Security .. 23 Private Key Protection .. 23 17. Audit .. 24 Eligible Audit Schemes .. 24 Audit Period .. 24 Audit Report .. 24 Pre-Issuance Readiness Audit .. 24 Audit of Delegated Functions .. 24 Auditor Qualifications .. 25 Key Generation Ceremony .. 25 Regular Quality Assessment Self Audits.

9 26 18. Liability and Indemnification .. 26 Liability to Subscribers and Relying Parties .. 26 Indemnification of Application Software Suppliers .. 26 Forum Guideline iv Root CA Obligations .. 26 Appendix A - Cryptographic Algorithm and Key Requirements (Normative) .. 27 Appendix B Certificate Extensions (Normative) .. 28 Root CA Certificate .. 28 Subordinate CA Certificate .. 28 Subscriber Certificate .. 29 Appendix C - User Agent Verification (Normative) .. 30 Forum Guideline CA / Browser Forum Baseline Requirements , v. 1 1. Scope The Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates describe a subset of the Requirements that a Certification Authority must meet in order to issue Publicly Trusted Certificates. Except where explicitly stated otherwise, these Requirements apply only to relevant events that occur on or after the Effective Date. These Requirements do not address all of the issues relevant to the issuance and management of Publicly-Trusted Certificates.

10 The CA/Browser Forum may update the Requirements from time to time, in order to address both existing and emerging threats to online security. In particular, it is expected that a future version will contain more formal and comprehensive audit Requirements for delegated functions. This version of the Requirements only addresses Certificates intended to be used for authenticating servers accessible through the Internet. Similar Requirements for code signing, S/MIME, time-stamping, VoIP, IM, Web services, etc. may be covered in future versions. These Requirements do not address the issuance, or management of Certificates by enterprises that operate their own Public Key Infrastructure for internal purposes only, and for which the Root Certificate is not distributed by any Application Software Supplier. 2. Purpose The primary goal of these Requirements is to enable efficient and secure electronic communication, while addressing user concerns about the trustworthiness of Certificates.


Related search queries