Skip to content

Make the CAB Forum Reserved Policy Identifier mandatory, and other policy OIDs optional #45

Description

@defacto64

I propose to require that "Subscriber Certificates MUST include a CA/Browser Forum Reserved Policy Identifier in the Certificate Policies extension", while allowing another CA-defined Policy OIDs as a "MAY".

In other words, I propose to modify the following language (§9.3.4) ....

A Certificate issued to a Subscriber MUST contain one or more policy identifier(s), defined by the
CA, in the Certificate’s certificatePolicies extension that indicates adherence to and compliance with
these Requirements. CAs complying with these Requirements MAY also assert the reserved policy
OIDs in such Certificates.

... like this:

CAs complying with these Requirements MUST include the CA/Browser Forum Reserved Policy OID (see section 9.3.1) in the Subscriber Certificate’s certificatePolicies extension. CAs MAY also assert in such Certificates one or more policy identifier(s), defined by the CA, that indicates adherence to and compliance with these Requirements.

This would allow to quickly and automatically determine if any given Certificate under examination is supposed to comply with the CABF CS BRs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions