RFC1422 , February 1993. [PKI1] Housley, R., Ford, W., Polk, W. and D. Solo, "Internet X.509 Public Key Infrastructure, Certificate and CRL Profile", RFC 2459, January 1999.8. AUTHORS' ADDRESSES Sant
RFC1422, February
1993.
[PKI1] Housley, R., Ford, W., Polk, W. and D. Solo, "Internet X.509
Public Key Infrastructure, Certificate and CRL Profile", RFC
2459, January 1999.
8. AUTHORS' ADDRESSES
Santosh Chokhani
CygnaCom Solutions, Inc.
Suite 100 West
7927 Jones Branch Drive
McLean, VA 22102
Phone: (703) 848-0883
Fax: (703) 848-0960
EMail:
chokhani@cygnacom.com
Warwick Ford
VeriSign, Inc.
301 Edgewater Place, Suite 210
Wakefield, MA 01880
Phone: (781) 245-6996 x225
Fax: (781) 245-6006
EMail:
wford@verisign.com
NOTES
1 The ABA Digital Signature Guidelines can be purchased from the ABA.
See
http://www.abanet.com for ordering details.
2 Examples of types of entity for subject CAs are a subordinate
organization (e.g., branch or division), a federal government
agency, or a state or provincial government department.
3 This statement can have significant implications. For example,
suppose a bank claims that it issues CA certificates to its
branches only. Now, the user of a CA certificate issued by the
bank can assume that the subject CA in the certificate is a branch
of the bank
4 Examples of the types of subject RA entities are branch and
division of an organization.
5 Examples of types of subject end entities are bank customers,
telephone company subscribers, and employees of a government
department
6 This statement can have significant implications. For example,
suppose Government CA claims that it issues certificates to
Government employees only. Now, the user of a certificate issued
by the Government CA can assume that the subject of the certificate
is a Government employee.
7 Examples include X.500 distinguished name, Internet e-mail address,
and URL.
8 The term "meaningful" means that the name form has commonly
understood semantics to determine identity of the person and/or
organization. Directory names and
RFC822 names may be more or
less meaningful.
9 Examples of proof include the issuing CA generating the key, or
requiring the subject to send an electronically signed request or
to sign a challenge.
10 Examples of organization identity authentication are: articles of
incorporation, duly signed corporate resolutions, company seal,
and notarized documents.
11 Examples of individual identity authentication are: biometrics
(thumb print, ten finger print, face, palm, and retina scan),
driver's license, passport, credit card, company badge, and
government badge.
12 Examples include duly signed authorization papers or corporate ID
badge.
13 The identification policy for routine rekey should be the same as
the one for initial registration since the same subject needs
rekeying. The rekey authentication may be accomplished using the
techniques for initial I&A or using digitally signed requests.
14 This identification and authentication policy could be the same as
that for initial registration.
15 This policy could be the same as the one for initial registration.
16 The identification policy for Revocation request could be the same
as that for initial registration since the same subject
certificate needs to be revoked. The authentication policy could
accept a Revocation request digitally signed by subject. The
authentication information used during initial registration could
be acceptable for Revocation request. Other less stringent
authentication policy could be defined.
17 The identification policy for key compromise notification could be
the same as the one for initial registration since the same
subject certificate needs to be revoked. The authentication
policy could accept a Revocation request digitally signed by
subject. The authentication information used during initial
registration could be acceptable for key compromise notification.
Other less stringent authentication policy could be defined.
18 The n out of m rule allows a key to be split in m parts. The m
parts may be given to m different individuals. Any n parts out of
the m parts may be used to fully reconstitute the key, but having
any n- 1 parts provides one with no information about the key.
19 A key may be escrowed, backed up or archived. Each of these
functions have different purpose. Thus, a key may go through any
subset of these functions depending on the requirements. The
purpose of escrow is to allow a third party (such as an
organization or government) to legally obtain the key without the
cooperation of the subject. The purpose of back up is to allow
the subject to reconstitute the key in case of the destruction of
the key. The purpose of archive is to provide for reuse of the
key in future, e.g., use the private key to decrypt a document.
20 An example of activation data is a PIN or passphrase.
21 Examples of physical access controls are: monitored facility ,
guarded facility, locked facility, access controlled using tokens,
access controlled using biometrics, and access controlled through
an access list.
22 Examples of the roles include system administrator, system
security officer, and system auditor. The duties of the system
administrator are to configure, generate, boot, and operate the
system. The duties of the system security officer are to assign
accounts and privileges. The duties of the system auditor are to
set up system audit profile, perform audit file management, and
audit review.
23 The background checks may include clearance level (e.g., none,
sensitive, confidential, secret, top secret, etc.) and the
clearance granting authority name. In lieu of or in addition to a
defined clearance, the background checks may include types of
background information (e.g., name, place of birth, date of birth,
home address, previous residences, previous employment, and any
other information that may help determine trustworthiness). The
description should also include which information was verified and
how.
24 For example, the certificate policy may impose personnel security
requirements on the network system administrator responsible for a
CA's network access.
25 Regardless of whether authorized persons are employees, practices
should be implemented to ensure that each authorized person is
held accountable for his/her actions.
26 A cryptographic module is hardware, software, or firmware or any
combination of them.
27 The compliance description should be specific and detailed. For
example, for each FIPS 140-1 requirement, describe the level and
whether the level has been certified by an accredited laboratory.
28 Example of audit events are: request to create a certificate,
request to revoke a certificate, key compromise notification,
creation of a certificate, revocation of a certificate, issuance
of a certificate, issuance of a CRL, issuance of key compromise
CRL, establishment of trusted roles on the CA, actions of truste
personnel, changes to CA keys, etc.
29 Example of archive events are: request to create a certificate,
request to revoke a certificate, key compromise notification,
creation of a certificate, revocation of a certificate, issuance
of a certificate, issuance of a CRL, issuance of key compromise
CRL, and changes to CA keys.
30 A parent CA is an example of audit relationship.
31 Example of compliance audit topics: sample check on the various
I&A policies, comprehensive checks on key management policies,
comprehensive checks on system security controls, comprehensive
checks on operations policy, and comprehensive checks on
certificate profiles.
32 The examples include, temporary suspension of operations until
deficiencies are corrected, revocation of entity certificate,
change in personnel, invocation of liability policy, more frequent
compliance audit, etc.
33 An organization may choose not to make public some of its security
controls, clearance procedures, or some others elements due to
their sensitivity.
34 All or some of the following items may be different for the
various types of entities, i.e., CA, RA, and end entities.
LIST OF ACRONYMS
ABA - American Bar Association
CA - Certification Authority
CPS - Certification Practice Statement
CRL - Certificate Revocation List
DAM - Draft Amendment
FIPS - Federal Information Processing Standard
I&A - Identification and Authentication
IEC - International Electrotechnical Commission
IETF - Internet Engineering Task Force
IP - Internet Protocol
ISO - International Organization for Standardization
ITU - International Telecommunications Union
NIST - National Institute of Standards and Technology
OID - Object Identifier
PIN - Personal Identification Number
PKI - Public Key Infrastructure
PKIX - Public Key Infrastructure (X.509) (IETF Working Group)
RA - Registration Authority
RFC- Request For Comment
URL - Uniform Resource Locator
US - United States
Full Copyright Statement
Copyright (C) The Internet Society (1999). All Rights Reserved.
This document and translations of it may be copied and furnished to
others, and derivative works that comment on or otherwise explain it
or assist in its implementation may be prepared, copied, published
and distributed, in whole or in part, without restriction of any
kind, provided that the above copyright notice and this paragraph are
included on all such copies and derivative works. However, this
document itself may not be modified in any way, such as by removing
the copyright notice or references to the Internet Society or other
Internet organizations, except as needed for the purpose of
developing Internet standards in which case the procedures for
copyrights defined in the Internet Standards process must be
followed, or as required to translate it into languages other than
English.
The limited permissions granted above are perpetual and will not be
revoked by the Internet Society or its successors or assigns.
This document and the information contained herein is provided on an
"AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING
TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING
BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION
HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.