This document is consistent with RFC 2527. Therefore there are some sections that are maintained for compatibility, although they do not apply exactly to the services required by the GRID projects. Glossary provides a glossary of terms used in this document.
Within this document the words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", "OPTIONAL" are to be interpreted as in RFC 2119. (See Appendix A).
In this document the expression "conforming CA" is used to indicate a CA whose behavior is conforming to the set of provisions specified in this document.
This CP describes the requirements which MUST be met by a conforming CA in issuing digital certificates for GRID users and services.
This CP MAY be used by a relying party to determine the level of trust associated with this policy. An X.509 Version 3 certificate issued by a conforming CA SHOULD contain a reference to this certificate policy.
More detailed information about the practices which a conforming CA employs in its operations in issuing certificates can be found in its Certification Practice Statements (CPS).
CESNETCAGRIDCertificatePolicyv1:1
This certificate policy is identified by the following unique registered Object Identifier (OID):
1.3.6.1.4.1.8057.1.2.1.1.1
Conforming CAs provide PKI services for the Czech academic community. Certificates issued under this CP are issued to users and services affiliated to organizations participating in GRID project.
Conforming CAs SHOULD be operated by organizations participating in the GRID projects.
Registration Authorities (RA) are needed for physical identification/authentication of entities. These authorities MUST not be permitted to issue certificates. The RA MUST sign an agreement with the certifying CA, stating the obligation to adhere to the agreed procedures as identified in the CA's CPS.
The conforming CA MAY manage the functions of its Registration Authority.
The targeted end entities are employees and students of Czech universities, employees of Czech Academy of Sciences, and any organizations cooperating with these entities in the GRID project as well as computers and application services operated by these organizations.
Certificates issued by a conforming CA MUST NOT be used for financial transactions.
This CP is maintained by CESNET a.l.e. (http://www.cesnet.cz/).
All questions and comments concerning this CPS must be addressed to:
CESNET CA
CESNET a.l.e.
Zikova 4
Prague
160 00
Czech Republic
Email: <ca@cesnet.cz>
URI: http://www.cesnet.cz/pki/