Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make the CAB Forum Reserved Policy Identifier mandatory, and other policy OIDs optional #45

Open
defacto64 opened this issue Feb 24, 2025 · 0 comments

Comments

@defacto64
Copy link

I propose to require that "Subscriber Certificates MUST include a CA/Browser Forum Reserved Policy Identifier in the Certificate Policies extension", while allowing another CA-defined Policy OIDs as a "MAY".

In other words, I propose to modify the following language (§9.3.4) ....

A Certificate issued to a Subscriber MUST contain one or more policy identifier(s), defined by the
CA, in the Certificate’s certificatePolicies extension that indicates adherence to and compliance with
these Requirements. CAs complying with these Requirements MAY also assert the reserved policy
OIDs in such Certificates.

... like this:

CAs complying with these Requirements MUST include the CA/Browser Forum Reserved Policy OID (see section 9.3.1) in the Subscriber Certificate’s certificatePolicies extension. CAs MAY also assert in such Certificates one or more policy identifier(s), defined by the CA, that indicates adherence to and compliance with these Requirements.

This would allow to quickly and automatically determine if any given Certificate under examination is supposed to comply with the CABF CS BRs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant