Viewable With ANY Browser

Note: My Web pages are best viewed with style sheets enabled.

Unrated

Certificate Authority Review Checklist

C. Operational Review

Copyright © 2005, 2007 by David E. Ross

Version 28Dec08-2.1.0

Verification of the requirements in this section will generally be done through on-site observations of the operations of the certificate authority.

C.1 Documentation Conformance

C.2 Security

C.3 Maintaining Root Certificates

C.4 Maintaining Intermediate Certificates

C.5 Generating Subscriber Certificates

C.6 Signing Subscriber Certificates

C.7 Renewing Certificates and Signatures

C.8 Revoking Certificates

C.9 Use of External Registration Authority

C.1 Documentation Conformance
Req. #WTRequirementVerifiedComments
C.1.a9The CA has been repeatedly observed to operate in general conformance with its CP.
C.1.b9The CA has been repeatedly observed to operate in general conformance with its CPS.
C.1.c9The CA has been repeatedly observed to operate in general conformance with its privacy policy.
C.1.d43CA personnel demonstrate knowledge of disaster recovery procedures (see §A.3.l).
C.2 Security
Req. #WTRequirementVerifiedComments
C.2.a43CA personnel demonstrate knowledge of proper security practices (see §A.5).
C.2.b18, 43The CA maintains current protection against:
  • being infected by computer viruses and other "malware"
  • distributing computer viruses and other "malware"
(See §A.5.f)
C.2.c18, 43The CA maintains current protection against "hacking", snooping, and other electronic intrusions into its computer systems (see §A.5.f).
C.2.d18, 43The CA protects computer systems and other hardware involved in certificate operations and subscriber records against theft and unauthorized physical and electronic access (see §A.5.f and §A.5.g).
C.3 Maintaining Root Certificates
Req. #WTRequirementVerifiedComments
C.3.a20The root certificate public key is readily available for downloading and installation by subscribers and the general public.
C.3.b20The root certificate public key can be readily authenticated by subscribers and the general public.
C.3.c18The root certificate private key is stored secure from electronic and physical compromise.
C.3.d18The root certificate private key is stored by the CA and not by any outside party.
C.3.e18The root certificate private key pass-phrase (i.e. password) is not stored electronically or physically.
C.3.f18The root certificate private key pass-phrase (or parts thereof) is known only to CA personnel.
C.3.g18Provision is made to prevent loss of the root certificate through a single-point of failure of electronic equipment (including physical destruction of such equipment).
C.3.h18Provision is made to prevent loss of use of the root certificate resulting from the loss of one key person.
C.3.i18Use of the root certificate private key requires cooperative action by at least two CA personnel.
C.3.j21All subscribers are notified immediately if the root certificate is revoked.
C.3.k21Provision is made for prompt re-signing of affected non-expired, non-revoked subscriber certificates with a new root certificate if the root certificate is revoked.
C.3.l18Expired and revoked root certificates are archived.
C.4 Maintaining Intermediate Certificates
(For the purpose of this Section C, second-party intermediate certificates of other CAs issued and signed by the CA under review and used to sign subscribers certificates issued by those second-party CAs are treated as subscriber certificates issued by the CA under review.)
Req. #WTRequirementVerifiedComments
C.4.a20Intermediate certificate public keys are readily available for downloading and installation by subscribers and the general public.
C.4.b18The intermediate certificate private keys are stored secure from electronic and physical compromise.
C.4.cNoneThe intermediate certificates are created by the CA and not by any outside party.
C.4.d18The intermediate certificate private key pass-phrases (or parts thereof) are known only to CA personnel.
C.4.e18The intermediate certificate private key pass-phrases are stored securely.
C.4.f21All affected subscribers are notified immediately if an intermediate certificate is revoked.
C.4.g21Provision is made for prompt re-signing of affected non-expired, non-revoked subscriber certificates with a new intermediate certificate if an intermediate certificate is revoked.
C.4.h18Expired and revoked intermediate certificates are archived.
C.5 Generating Subscriber Certificates
Req. #WTRequirementVerifiedComments
C.5.a19If the CA generates certificates for its subscribers, all requirements for signing subscriber certificates are met (see §C.6).
C.5.b19, 23If the CA generates certificates for its subscribers, a subscriber's private key is stored with the same security as the CA's key that signed the subscriber's certificate.
C.5.c22If the CA generates certificates for its subscribers, a subscriber's private key is communicated to the subscriber in a secure manner.
C.5.dNoneIf the CA generates certificates for its subscribers, a subscriber is immediately advised to change its certificate's pass-phrase.
C.5.eNonePass-phrases for CA-generated subscriber certificates are randomly generated.
C.5.f23A record of the pass-phrase for a CA-generated subscriber certificate is not retained beyond delivery of the certificate to the subscriber.
C.5.gNoneThe pass-phrase for a CA-generated subscriber certificate is communicated to the subscriber in a secure manner separately from the corresponding private key.
C.5.hNoneIf the CA generates certificates for its subscribers, the user ID chosen by the subscriber properly appears in the certificate.
C.6 Signing Subscriber Certificates
Req. #WTRequirementVerifiedComments
C.6.a25Positive identity of a subscriber is obtained prior to signing a subscriber's certificate.
C.6.b22, 25Prior to signing a subscriber's certificate, the purposes contained within the certificate is verified to agree with the purposes in the subscriber's request for signatures (see §A.2.l).
C.6.c25For subscriber E-mail certificates, the E-mail address in the certificate matches the address in the subscriber's application for signature (see §A.2.g).
C.6.d25For subscriber site certificates, the domain in the certificate matches the domain in the subscriber's application for signature (see §A.2.h).
C.6.e25When an individual requests a certificate to be signed and the subscriber is an organization, the following are positively verified:
  • the individual's identity
  • the individual's authorization to request a signature on the certificate
C.6.f11Certificates are signed in a timely manner.
C.6.g13The public list of subscriber certificates (see §B.2.h) is updated in a timely manner to show newly signed certificates.
C.7 Renewing Certificates and Signatures
Req. #WTRequirementVerifiedComments
C.7.a27The CA notifies the affected subscriber in a timely manner when a certificate generated by the CA is about to expire.
C.7.b27, 29The same care is taken during the renewal of a certificate generated by the CA as was taken during the certificate's initial issue (see §C.5).
C.7.c27The CA notifies the affected subscriber in a timely manner when the CA's signature on a certificate is about to expire.
C.7.d27, 29The same care is taken during the renewal of a certificate's signature as was taken during the certificate's initial signing (see §C.6).
C.7.e27, 29Replacing a certificate that already expired is handled in accord with the CP (see §A.2.s) with the same care as for a certificate about to expire (as indicated in this §C.7).
C.7.fNoneBefore renewing a site certificate, the domain registration is verified that the domain owner has not changed.
C.8 Revoking Certificates
(In terms of the CA's operations, revoking a subscriber's certificate
and merely revoking the CA's signature thereon might be treated the same.)
Req. #WTRequirementVerifiedComments
C.8.a33Revoking a subscriber's certificate is performed in accord with the CP (see §A.2.p).
C.8.b33Positive identity of a subscriber is obtained before the CA acts on the subscriber's request to revoke a certificate.
C.8.c33Certificates are revoked promptly.
C.8.d33A subscriber is required to notify the CA promptly if the subscriber revokes its own key. Such notification must include positive identification of the subscriber.
C.8.eNoneReplacing a revoked certificate is handled in accord with the CP (see §A.2.s) and with the same care as for a certificate about to expire (see §C.7).
C.8.f33, 35The public list of revoked certificates (see §B.2.j) is updated promptly.
C.9 Use of External Registration Authority
Req. #WTRequirementVerifiedComments
C.9.a25, 26When the CA uses an external registration authority (RA), each RA is positively identified by CA personnel before being authorized to verify identities of subscribers and authorizations of individuals to represent organizational subscribers (see §A.2.v).
C.9.b26RAs provide the CA with complete documentation on each verified applicant for a certificate (see §A.2.w).
C.9.c26RAs provide the CA with complete documentation on each verified authorized individual representing an organizational subscriber (see §A.2.x).

Last updated 2 July 2007

Valid HTML 4.01