Policy 2.8: MRSP Issue #238: Clarify that CAs can generate their own keys

54 kali dilihat
Langsung ke pesan pertama yang belum dibaca

Ben Wilson

belum dibaca,
4 Apr 2022, 13.46.4504/04/22

I intend to address a minor issue in this batch of changes for MRSP v. 2.8. 

Currently, section 5.2 of the MRSP says, "CAs MUST NOT generate the key pairs for end-entity certificates that have an EKU extension containing the KeyPurposeIds id-kp-serverAuth or anyExtendedKeyUsage."  However, if the CA is creating end-entity certificates for itself, e.g. certificates for test websites as required by section 2.2 of the Baseline Requirements, then this language presents a problem. See https://github.com/mozilla/pkipolicy/issues/238

Here is proposed language to address this issue, add to the end of the phrase above, "unless the certificate is being issued to the CA itself."

Please review.


Ben Wilson

Balas ke semua
Balas ke penulis
0 pesan baru