7. CERTIFICATE AND CRL PROFILES

7.1. Certificate Profile

In order to promote interoperability this policy strongly encourages conforming CA to issue certificates profiling them accordingly to RFC 2459. In every case CPS MUST detail the specific profile adopted.

7.1.1. Version number(s)

The version field in the certificate SHALL state 2, indicating X.509v3 certificates.

7.1.2. Certificate extensions

In compliance with RFC 2459, the inclusion of the following certificate extensions is RECOMMENDED:

subjectKeyIdentifierNOT CRITICAL
authorityKeyIdentifierNOT CRITICAL
basicConstraintsCRITICAL
keyUsageCRITICAL
certificatePoliciesNOT CRITICAL

It is also RECOMMENDED the use of other two extensions: cRLDistributionPoint for providing information useful to retrieve the CRL, and subjectAltNames when there is the need to include an RFC822 e-mail address to a certificate. Both these two extensions SHOULD be marked as NOT CRITICAL.

7.1.4. Name forms

All related issues MUST be specified in the CPS.

7.1.5. Name constraints

All related issues MUST be specified in the CPS.

7.1.6. Certificate policy Object Identifier

Other certificate policy object identifiers are applicable if and only if the other policies identified are compliant with this policy. Conforming CA MUST contact the maintainers of the various policies to verify the level of mutual compliance. However in order to promote interoperability, following RFC 2459, this policy suggests to include only one certificate policy object identifier in a certificate.

7.1.7. Usage of Policy Constraints extension

All related issues MUST be specified in the CPS.

7.1.8. Policy qualifiers syntax and semantics

The Certificate Policies extension field has a provision for conveying, along with each certificate policy identifier, additional policy-dependent information in a qualifier field. The certificates issued under this CP SHOULD NOT use the policy qualifiers.

7.2. CRL Profile

7.2.1. Version number(s)

The version field in the certificate SHALL be omitted, indicating X.509v1 CRL.