X509 Certificate Policies extension
hi all
have 3 tire pki hierarchy: root ca, intermediate ca , issuing cas. our intermediate ca has own cps(certificate practice statement) uses root's cp(certificate policy).
problem oid should used in "certificate policies" extension of our new issuing ca's certificates , end entity's certificate?
have done research , according rfc 5280 oid should point policies certificate issued under. found out extension used in path validation algorithms.
oid should extension point to? cp's or cps's? 1 best practice?
have 3 tire pki hierarchy: root ca, intermediate ca , issuing cas. our intermediate ca has own cps(certificate practice statement) uses root's cp(certificate policy).
problem oid should used in "certificate policies" extension of our new issuing ca's certificates , end entity's certificate?
have done research , according rfc 5280 oid should point policies certificate issued under. found out extension used in path validation algorithms.
oid should extension point to? cp's or cps's? 1 best practice?
the extensions should point cp oids (defining each assurance level available in issued certificate).
in 3 tiered hierarchy, following (assuming 3 assurance levels).
root: issuance policies
policy tier:lowoid, mediumoid, highoid
issuing ca 1: lowoid, mediumoid, highoid (or 1 oid or 2 oids selection)
issuing ca 2: lowoid, mediumoid, highoid (or 1 oid or 2 oids selection)
brian
Windows Server > Security
Comments
Post a Comment