This Certificate Policy defines the Basic Level certificate policy for use by the conforming CAs when issuing public key certificates.
This document is consistent with RFC 2527. Therefore there are some sections that are maintained for compatibility, although they do not apply exactly to the services required by this CP. Glossary provides a glossary of terms used in this document.
Within this document the words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", "OPTIONAL" are to be interpreted as in RFC 2119. (See Appendix A).
In this document the expression "conforming CA" is used to indicate a CA whose behavior is conforming to the set of provisions specified in this document.
This CP describes the requirements which MUST be met by a conforming CA in issuing digital certificates.
This CP MAY be used by a relying party to determine the level of trust associated with this policy. An X.509 Version 3 certificate issued by a conforming CA SHOULD contain a reference to this certificate policy.
More detailed information about the practices which a conforming CA employs in its operations in issuing certificates can be found in its Certification Practice Statements (CPS).
CESNETCABasicCertificatePolicyv1:1
This certificate policy is identified by the following unique registered Object Identifier (OID):
Conforming CAs can choose freely which are the community and applicability of their issued certificates but it MUST clearly specify them in its own CPS.
Conforming CAs MUST operate in full conformance with this CP.
Registration Authorities (RA) are needed for physical identification/authentication of entities. These authorities MUST not be permitted to issue certificates. The RA MUST sign an agreement with the certifying CA, stating the obligation to adhere to the agreed procedures as identified in the CA's CPS.
The conforming CA MAY manage the functions of its Registration Authority.
The targeted end entities can be a natural person (individual or representing an organization) or a computer entity (e.g. a computer, a router or an application), capable of performing cryptographic operations.
Each conforming CA MUST detail in the CPS who are the end entities that it is willing to certify.
Certificates issued by a conforming CA MUST NOT be used for financial transactions.
This CP is maintained by CESNET a.l.e. (http://www.cesnet.cz/).
All questions and comments concerning this CP must be addressed to:
CESNET CA
CESNET a.l.e.
Zikova 4
Prague
160 00
Czech Republic
Email: <ca@cesnet.cz>
URI: http://www.cesnet.cz/pki/