The Nisu Team Certification Authority
Certificate Practice Statement (CPS).
Introduction
Community and Applicability
Certification authorities
Contact Details
Specification administration organization
Person determining CPS suitability for the policy
General provisions
Obligations
Relying party obligations
Financial responsibility
Indemnification by relying parties
Interpretation and Enforcement
Severability, survival, merger, notice
Dispute resolution procedures
Fees
Certificate issuance or renewal fees
Revocation or status information access fees
Fees for other services such as policy information
Publication and Repository
Publication of CA information
Compliance audit
Frequency of entity compliance audit
Identity/qualifications of auditor
Auditor's relationship to audited party
Actions taken as a result of deficiency
Confidentiality
Types of information to be kept confidential
Types of information not considered confidential
Disclosure of certificate revocation/suspension information
Release to law enforcement officials
Release as part of civil discovery
Disclosure upon owner's request
Other information release circumstances
Intellectual Property Rights
Identification and Authentication
Initial Registration
Need for names to be meaningful
Rules for interpreting various name forms
Name claim dispute resolution procedure
Recognition, authentication and role of trademarks
Method to prove possession of private key
Authentication of organization identity
Authentication of individual identity
Operational Requirements
Certificate Suspension and Revocation
Circumstances for revocation
Who can request revocation
Procedure for revocation request
Revocation request grace period
Circumstances for suspension
Who can request suspension
Procedure for suspension request
Limits on suspension period
CRL issuance frequency (if applicable)
CRL checking requirements
On-line revocation/status checking availability
On-line revocation checking requirements
Other forms of revocation advertisements available
Checking requirements for other forms of revocation advertisements
Special requirements re key compromise
Security Audit Procedures
Frequency of processing log
Retention period for audit log
Audit log backup procedures
Audit collection system (internal vs external)
Notification to event-causing subject
Vulnerability assessments
Records Archival
Retention period for archive
Archive backup procedures
Requirements for time-stamping of records
Archive collection system (internal or external)
Procedures to obtain and verify archive information
Compromise and Disaster Recovery
Computing resources, software, and/or data are corrupted
Entity public key is revoked
Entity key is compromised
Secure facility after a natural or other type of disaster
Physical, Procedural, and Personnel Security Controls
Physical Controls
Site location and construction
Power and air conditioning
Fire prevention and protection
Procedural Controls
Number of persons required per task
Identification and authentication for each role
Personnel Controls
Background, qualifications, experience, and clearance requirements
Background check procedures
Retraining frequency and requirements
Job rotation frequency and sequence
Sanctions for unauthorized actions
Contracting personnel requirements
Documentation supplied to personnel
Technical Security Controls
Key Pair Generation and Installation
Private key delivery to entity
Public key delivery to certificate issuer
CA public key delivery to users
Public key parameters generation
Parameter quality checking
Hardware/software key generation
Key usage purposes (as per X v key usage field)
Private Key Protection
Standards for cryptographic module
Private key (n out of m) multi-person control
Private key entry into cryptographic module
Method of activating private key
Method of deactivating private key
Method of destroying private key
Other Aspects of Key Pair Management
Usage periods for the public and private keys
Activation Data
Activation data generation and installation
Activation data protection
Other aspects of activation data
Computer Security Controls
Specific computer security technical requirements
Life Cycle Technical Controls
System development controls
Security management controls
Life cycle security ratings
Network Security Controls
Cryptographic Module Engineering Controls
Certificate and CRL Profiles
Certificate Profile
Algorithm object identifiers
Certificate policy Object Identifier
Usage of Policy Constraints extension
Policy qualifiers syntax and semantics
Processing semantics for the critical certificate policy extension
CRL Profile
CRL and CRL entry extensions
Specification Administration
Specification change procedures
Publication and notification policies
Select Style