Template Certificate Practice Statement
Total Page:16
File Type:pdf, Size:1020Kb
<Please enter Company Logo> [COMPANY CA] Certification Practice Statement Date: [PUBLICATION DATE] Version: v. X.X [COMPANY] Certification Practice Statement Table of Contents Document History ...............................................................................................................................1 Acknowledgments ..............................................................................................................................2 1. Introduction ............................................................................................................................3 1.1 Overview ................................................................................................................................3 1.2 [COMPANY] Certificate types ................................................................................................4 1.2.1 [Server] Certificates ...............................................................................................................4 1.2.1 [Client] Certificates ................................................................................................................4 1.2.2 Acceptable Subscriber Names ..............................................................................................4 1.2.3 Pseudonyms ..........................................................................................................................4 1.2.4 Registration Procedures ........................................................................................................5 1.3 [COMPANY] [Server] certificates...........................................................................................5 1.3.1 General ..................................................................................................................................5 1.3.2 Certificate Request ................................................................................................................5 1.3.3 Content ..................................................................................................................................5 1.3.4 Information Submitted to Verify Ownership or Right to Use of the Domain Name ...............5 1.3.5 Issuing Procedure ..................................................................................................................5 1.3.6 Limited Warranty ...................................................................................................................6 1.3.7 Relevant [COMPANY] Documents ........................................................................................6 1.4 [COMPANY] [Client] Certificates ...........................................................................................6 1.4.1 General ..................................................................................................................................6 1.4.2 Certificate Request ................................................................................................................6 1.4.3 Content ..................................................................................................................................7 1.4.4 Documents Submitted to Identify the Applicant .....................................................................7 1.4.5 Issuing Procedure ..................................................................................................................7 1.4.6 Limited Warranty ...................................................................................................................7 1.4.7 Relevant [Company] Documents ...........................................................................................7 1.5 Certificate usages ..................................................................................................................7 1.6 Document Name and Identification .......................................................................................8 1.7 PKI Participants .....................................................................................................................8 1.7.1 [COMPANY] Certification Authority .......................................................................................8 1.7.2 Subscribers ............................................................................................................................9 1.7.3 Relying Parties.......................................................................................................................9 1.8 Certificate Use .......................................................................................................................9 1.8.1 Appropriate Certificate Usage ...............................................................................................9 1.8.2 Prohibited Certificate Usage ............................................................................................... 10 1.8.3 Certificate Extensions ......................................................................................................... 10 1.8.4 Critical Extensions .............................................................................................................. 10 1.9 Policy Administration .......................................................................................................... 10 1.9.1 Scope .................................................................................................................................. 10 1.9.2 [COMPANY] Policy Management Authority ....................................................................... 10 1.9.3 Acceptance of Updated Versions of the CPS ..................................................................... 10 1.9.4 Version Management and Denoting Changes ................................................................... 10 1.10 Definitions and Acronyms ................................................................................................... 11 2. Publication and Repository Responsibilities ....................................................................... 12 3. Identification and Authentication ........................................................................................ 13 3.1 Initial Identity Validation ...................................................................................................... 13 3.2 Subscriber Registration Process ........................................................................................ 13 3.2.1 Documents Used for Subscriber Registration .................................................................... 13 3.2.2 Records for Subscriber Registration .................................................................................. 13 3.2.3 Identification and Authentication for Revocation Requests ................................................ 14 4. Certificate Life-Cycle Operational Requirements ............................................................... 15 4.1 Certificate Application Processing and Issuance ............................................................... 15 4.2 Certificate Generation ......................................................................................................... 15 4.3 Certificate Acceptance ........................................................................................................ 15 4.4 Key Pair and Certificate Usage .......................................................................................... 16 4.4.1 Subscriber ........................................................................................................................... 16 4.4.2 Relying Party ...................................................................................................................... 16 4.5 Certificate Renewal ............................................................................................................ 17 [COMPANY] Certification Practice Statement Version: v. X.X [COMPANY] Certification Practice Statement 4.6 Certificate Revocation ........................................................................................................ 17 4.7 Certificate Status Services ................................................................................................. 18 4.8 End of Subscription ............................................................................................................ 18 4.9 Certificates Problem Reporting and Response Capability ................................................. 18 5. Management, Operational, And Physical Controls............................................................. 19 5.1 Physical Security Controls .................................................................................................. 19 5.2 Procedural Controls ............................................................................................................ 19 5.3 Personnel Security Controls ............................................................................................... 20 5.3.1 Qualifications, Experience, Clearances .............................................................................. 20 5.3.2 Training Requirements and Procedures ............................................................................. 20 5.3.3 Retraining Period and Retraining Procedures .................................................................... 20 5.3.4 Sanctions against Personnel .............................................................................................. 20 5.3.5 Controls of