X509 Certificate Policies extension


hi all
have 3 tire pki hierarchy: root ca, intermediate ca , issuing cas. our intermediate ca has own cps(certificate practice statement) uses root's cp(certificate policy).
problem oid should used in "certificate policies" extension of our new issuing ca's certificates , end entity's certificate?
have done research , according rfc 5280 oid should point policies certificate issued under. found out extension used in path validation algorithms.
oid should extension point to? cp's or cps's? 1 best practice?

the extensions should point cp oids (defining each assurance level available in issued certificate).

 in 3 tiered hierarchy, following (assuming 3 assurance levels).

root: issuance policies

policy tier:lowoid, mediumoid, highoid

issuing ca 1: lowoid, mediumoid, highoid (or 1 oid or 2 oids selection)

issuing ca 2: lowoid, mediumoid, highoid (or 1 oid or 2 oids selection)

brian



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client