Dear Mozilla team,
I have a clarification that I need to discuss with you please.
We have a 2-level CA hierarchy where the Root CA sits at the top level while Issuing CAs comes at the second level.
As part of the regular issuing CA re-key, we are going to add technical constraints to all issuing CAs in order to have separate Issuer CAs for Server Authentication, Code Signing, and Time Stamping uses. That will be reflected to the Issuing CAs’ certificates as follows:
|
Issuing CA |
EKU |
|
Devices Certification Authority |
serverAuth clientAuth |
|
Corporate Certification Authority |
clientAuth Microsoft Document Signing (1.3.6.1.4.1.311.10.3.12) |
|
Code Signing Certification Authority |
codeSigning |
|
Timestamping Certification Authority |
timeStamping |
According to our reading of Mozilla policy section 1.1, and given the above constraints; we assume that the Corporate Certification Authority and its underlying certificates (EE certificates) don’t fall under Mozilla’s scope. Could you please confirm?
Kindly note that the rationale behind our question is that there cases where we will not be able to have an EKU in EE certificates issued by the Corporate Certification Authority when the purpose/use of certificate is not matching with any of the standard EKUs.
Thank you in advance.
Kind Regards,
|
||||||||||||||||||||||
|
||||||||||||||||||||||
|
||||||||||||||||||||||
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/55dfa2e791e54c0995ddd7b13f14f610%40desc.gov.ae.
Chema López
Director Área Innovación, Cumplimiento y Tecnología

Barcelona Av. Torre Blanca 57, Edif. Esadecreapolis, Local 3B6 - 08173 Sant Cugat del Vallès | +34 934 774 245
Madrid C/ Velázquez 59, 1º Ctro-Izda. - 28001 Madrid | +34 915 762 181
El contenido de este correo electrónico y de sus anexos es confidencial. Si usted recibe este mensaje por error, debe saber que está prohibido hacer uso, divulgación y/o copia del mismo. En tal caso le agradeceríamos que advierta de inmediato a su remitente y que proceda a destruir el mensaje.
Le informamos que, cumpliendo la normativa en materia de protección de datos, FIRMAPROFESIONAL tratará sus datos con la finalidad de garantizar las relaciones con la empresa, entidad u organización a la que usted representa o en la que trabaja y por el período que dure dicha relación. Podrá ejercer sus derechos de acceso, rectificación, supresión, limitación, portabilidad y oposición al tratamiento ante el Responsable: FIRMAPROFESIONAL, S.A., Av. Torre Blanca, 57, local 3B6 (Edificio Esadecreapolis), 08173 Sant Cugat del Vallès (Barcelona), o bien mediante correo electrónico a: rg...@firmaprofesional.com, en cualquier caso adjuntando una copia de su D.N.I. o documento equivalente. Asimismo, podrá formular reclamaciones ante la Agencia Española de Protección de Datos. Para más información puede consultar nuestra política de privacidad.
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtaajNVxFxo-pfT--Gs1ydspDMvFoT9FSrrMTQhtH2JwkBw%40mail.gmail.com.
Thank you Ben and Chema, I definitely agree with your view on having proper EKUs in all leaf certificates.
However, I would appreciate your advice on situations where a certificate is meant to be used for document signing or transaction signing (e.g. signature verification response signing), in which case what would be the right EKU? even the Document Signing EKU=1.3.6.1.4.1.311.10.3.12 is actually used for signing documents within MS Office and it is not required for other document signing uses. That was the main reason behind my clarification really.
Kind Regards,
Chema López
Director Área Innovación, Cumplimiento y Tecnología

Barcelona Av. Torre Blanca 57, Edif. Esadecreapolis, Local 3B6 - 08173 Sant Cugat del Vallès | +34 934 774 245
Madrid C/ Velázquez 59, 1º Ctro-Izda. - 28001 Madrid | +34 915 762 181