Example: quiz answers

GlobalSign Certificate Policy

CA Digitally signed by CA Governance Governance Policy Authority Policy Date: Authority 15:26:08 +02'00'. GlobalSign Certificate Policy Date: September 30, 2021. Effective date for Qualified Timestamping, Qualified Web Authentication Certificates, Qualified Certificates for Electronic Signatures and Qualified Certificates for Electronic Seals: {normal date + 2 weeks}. Version: Table of Contents TABLE OF CONTENTS .. 2. DOCUMENT HISTORY .. 8. ACKNOWLEDGMENTS ..10. INTRODUCTION ..11. OVERVIEW .. 12. Certificate Naming .. 13. Additional requirements for Trusted Root Issuer CAs .. 15. DOCUMENT NAME AND IDENTIFICATION .. 16. PKI PARTICIPANTS .. 22. Certification Authorities ( Issuer CAs ) .. 22. Registration Authorities .. 22. Subscribers .. 23. Relying Parties .. 24. Other Participants .. 24. Certificate USAGE .. 24. Appropriate Certificate Usage .. 24. Prohibited Certificate Usage .. 24.

Sep 30, 2021 · GlobalSign Certificate Policy Date: September 30, 2021 Effective date for Qualified Timestamping, Qualified Web Authentication Certificates, Qualified Certificates for Electronic Signatures and Qualified Certificates for Electronic

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of GlobalSign Certificate Policy

1 CA Digitally signed by CA Governance Governance Policy Authority Policy Date: Authority 15:26:08 +02'00'. GlobalSign Certificate Policy Date: September 30, 2021. Effective date for Qualified Timestamping, Qualified Web Authentication Certificates, Qualified Certificates for Electronic Signatures and Qualified Certificates for Electronic Seals: {normal date + 2 weeks}. Version: Table of Contents TABLE OF CONTENTS .. 2. DOCUMENT HISTORY .. 8. ACKNOWLEDGMENTS ..10. INTRODUCTION ..11. OVERVIEW .. 12. Certificate Naming .. 13. Additional requirements for Trusted Root Issuer CAs .. 15. DOCUMENT NAME AND IDENTIFICATION .. 16. PKI PARTICIPANTS .. 22. Certification Authorities ( Issuer CAs ) .. 22. Registration Authorities .. 22. Subscribers .. 23. Relying Parties .. 24. Other Participants .. 24. Certificate USAGE .. 24. Appropriate Certificate Usage .. 24. Prohibited Certificate Usage .. 24.

2 Policy ADMINISTRATION .. 25. Organization Administering the Document .. 25. Contact Person .. 25. Person Determining CP Suitability for the Policy .. 25. CP Approval Procedures .. 26. DEFINITIONS AND ACRONYMS .. 26. PUBLICATION AND REPOSITORY RESPONSIBILITIES ..35. REPOSITORIES .. 35. PUBLICATION OF Certificate INFORMATION .. 35. TIME OR FREQUENCY OF 35. ACCESS CONTROLS ON REPOSITORIES .. 35. IDENTIFICATION AND AUTHENTICATION ..35. NAMING .. 36. Types of 36. Need for Names to be Meaningful .. 36. Anonymity or Pseudonymity of Subscribers .. 36. Rules for Interpreting Various Name Forms .. 36. Uniqueness of Names .. 36. Recognition, Authentication, and Role of Trademarks .. 36. INITIAL IDENTITY 36. Method to Prove Possession of Private Key .. 36. Authentication of Organization Identity .. 36. Authentication of Individual identity .. 38. Non-Verified Subscriber Information .. 42. Validation of Authority.

3 42. Criteria for Interoperation .. 44. Authentication of Domain Name .. 44. Authentication of Email addresses .. 44. IDENTIFICATION AND AUTHENTICATION FOR RE-KEY 44. Identification and Authentication for Routine Re-key .. 44. Identification and Authentication for Reissuance after Revocation .. 45. Re-verification and Revalidation of Identity When Certificate Information Changes .. 45. Identification and Authentication for Re-key After Revocation .. 45. GlobalSign CP ( Certificate Policy ) 2 of 81. Version: IDENTIFICATION AND AUTHENTICATION FOR REVOCATION REQUEST .. 45. Certificate LIFE CYCLE OPERATIONAL REQUIREMENTS ..46. Certificate APPLICATION .. 46. Who Can Submit a Certificate Application .. 46. Enrollment Process and Responsibilities .. 46. Certificate APPLICATION PROCESSING .. 46. Performing Identification and Authentication Functions .. 46. Approval or Rejection of Certificate Applications.

4 46. Time to Process Certificate Applications .. 46. Certificate ISSUANCE .. 47. CA Actions during Certificate Issuance .. 47. Notifications to Subscriber by the CA of Issuance of Certificate .. 47. Notification to North American Energy Standards Board (NAESB) Subscribers by the CA of Issuance of Certificate .. 47. Certificate ACCEPTANCE .. 47. Conduct Constituting Certificate Acceptance .. 47. Publication of the Certificate by the CA .. 47. Notification of Certificate Issuance by the CA to Other Entities .. 47. KEY PAIR AND Certificate 47. Subscriber Private Key and Certificate Usage .. 47. Relying Party Public Key and Certificate Usage .. 48. Certificate RENEWAL .. 48. Circumstances for Certificate Renewal .. 48. Who May Request Renewal .. 48. Processing Certificate Renewal Requests .. 48. Notification of New Certificate Issuance to Subscriber .. 48. Conduct Constituting Acceptance of a Renewal Certificate .

5 48. Publication of the Renewal Certificate by the CA .. 48. Notification of Certificate Issuance by the CA to Other Entities .. 48. Certificate RE-KEY .. 48. Circumstances for Certificate Re-Key .. 48. Who May Request Certification of a New Public Key .. 49. Processing Certificate Re-Keying Requests .. 49. Notification of New Certificate Issuance to Subscriber .. 49. Conduct Constituting Acceptance of a Re-Keyed Certificate .. 49. Publication of the Re-Keyed Certificate by the CA .. 49. Notification of Certificate Issuance by the CA to Other Entities .. 49. Certificate MODIFICATION .. 49. Circumstances for Certificate Modification .. 49. Who May Request Certificate 49. Processing Certificate Modification Requests .. 49. Notification of New Certificate Issuance to Subscriber .. 50. Conduct Constituting Acceptance of Modified Certificate .. 50. Publication of the Modified Certificate by the CA.

6 50. Notification of Certificate Issuance by the CA to Other Entities .. 50. Certificate REVOCATION AND SUSPENSION .. 50. Circumstances for Revocation .. 50. Who Can Request Revocation .. 52. Procedure for Revocation Request .. 52. Revocation Request Grace Period .. 53. Time Within Which CA Must Process the Revocation Request .. 53. Revocation Checking Requirements for Relying Parties .. 53. CRL Issuance Frequency .. 53. Maximum Latency for CRLs .. 54. On-Line Revocation/Status Checking Availability .. 54. On-Line Revocation Checking Requirements .. 54. GlobalSign CP ( Certificate Policy ) 3 of 81. Version: Other Forms of Revocation Advertisements Available .. 54. Special Requirements Related to Key Compromise .. 54. Circumstances for Suspension .. 55. Who Can Request Suspension .. 55. Procedure for Suspension 55. Limits on Suspension Period .. 55. Certificate STATUS SERVICES .. 55. Operational Characteristics.

7 55. Service Availability .. 55. Operational Features .. 55. END OF 55. KEY ESCROW AND RECOVERY .. 56. Key Escrow and Recovery Policy and Practices .. 56. Session Key Encapsulation and Recovery Policy and Practices .. 56. FACILITY, MANAGEMENT, AND OPERATIONAL CONTROLS ..56. PHYSICAL CONTROLS .. 56. Site Location and Construction .. 56. Physical 56. Power and Air Conditioning .. 56. Water Exposures .. 56. Fire Prevention and Protection .. 56. Media Storage .. 56. Waste Disposal .. 56. Off-Site Backup .. 57. PROCEDURAL CONTROLS .. 57. Trusted Roles .. 57. Number of Persons Required per Task .. 57. Identification and Authentication for Each Role .. 57. Roles Requiring Separation of 57. PERSONNEL CONTROLS .. 58. Qualifications, Experience, and Clearance 58. Background Check Procedures .. 58. Training 58. Retraining Frequency and Requirements .. 58. Job Rotation Frequency and Sequence.

8 59. Sanctions for Unauthorized Actions .. 59. Independent Contractor Requirements .. 59. Documentation Supplied to 59. AUDIT LOGGING PROCEDURES .. 59. Types of Events Recorded .. 59. Frequency of Processing Log .. 60. Retention Period for Audit Log .. 60. Protection of Audit Log .. 60. Audit Log Backup Procedures .. 60. Audit Collection System .. 60. Notification to Event-Causing Subject .. 60. Vulnerability Assessments .. 60. RECORDS ARCHIVAL .. 61. Types of Records Archived .. 61. Retention Period for Archive .. 61. Protection of Archive .. 61. Archive Backup Procedures .. 61. Requirements for Timestamping of Records .. 61. Archive Collection System (Internal or External) .. 61. Procedures to Obtain and Verify Archive Information .. 61. KEY CHANGEOVER .. 61. GlobalSign CP ( Certificate Policy ) 4 of 81. Version: COMPROMISE AND DISASTER RECOVERY .. 61. Incident and Compromise Handling Procedures.

9 61. Computing Resources, Software, and/or Data Are Corrupted .. 62. Issuing CA Private Key Compromise Procedures .. 62. Business Continuity Capabilities After a Disaster .. 62. CA OR RA TERMINATION .. 62. Successor Issuing Certification Authority .. 63. TECHNICAL SECURITY KEY PAIR GENERATION AND INSTALLATION .. 63. Key Pair Generation .. 63. Private Key Delivery to Subscriber .. 63. Public Key Delivery to Certificate Issuer .. 64. CA Public Key Delivery to Relying Parties .. 64. Key 64. Public Key Parameters Generation and Quality Checking .. 64. Key Usage Purposes (as per v3 Key Usage Field) .. 64. PRIVATE KEY PROTECTION AND CRYPTOGRAPHIC MODULE ENGINEERING CONTROLS .. 64. Cryptographic Module Standards and Controls .. 64. Private Key (n out of m) Multi-Person Control .. 65. Private Key Escrow .. 65. Private Key Backup .. 65. Private Key Archival .. 65. Private Key Transfer into or from a Cryptographic Module.

10 65. Private Key Storage on Cryptographic Module .. 65. Method of Activating Private Key .. 65. Method of Deactivating Private Key .. 65. Method of Destroying Private Key .. 65. Cryptographic Module Rating .. 65. OTHER ASPECTS OF KEY PAIR 66. Public Key Archival .. 66. Certificate Operational Periods and Key Pair Usage Periods .. 66. ACTIVATION DATA .. 66. Activation Data Generation and Installation .. 66. Activation Data Protection .. 66. Other Aspects of Activation Data .. 67. COMPUTER SECURITY CONTROLS .. 67. Specific Computer Security Technical Requirements .. 67. Computer Security Rating .. 67. LIFE CYCLE TECHNICAL CONTROLS .. 67. System Development Controls .. 67. Security Management Controls .. 67. Life Cycle Security Controls .. 68. NETWORK SECURITY CONTROLS .. 68. TIMESTAMPING .. 68. Certificate , CRL, AND OCSP PROFILES ..68. Certificate 68. Version Number(s) .. 68. Certificate Extensions.


Related search queries