Zde můžete vidět rozdíly mezi vybranou verzí a aktuální verzí dané stránky.
Obě strany předchozí revize Předchozí verze Následující verze | Předchozí verze | ||
en:st-cca-services.html [2011/12/15 01:16] sova@cesnet.cz |
en:st-cca-services.html [2022/03/08 14:35] (aktuální) Jan Chvojka [Server CESNET CA 4 Certificates] |
||
---|---|---|---|
Řádek 4: | Řádek 4: | ||
Services provided by the CESNET PKI are described in certificate policies and Certificate Practice Statement available in the chapter [[ch-cp-cps.html|Certificate Policies and Certificate Practice Statement]]. | Services provided by the CESNET PKI are described in certificate policies and Certificate Practice Statement available in the chapter [[ch-cp-cps.html|Certificate Policies and Certificate Practice Statement]]. | ||
+ | |||
+ | CESNET CA is not accredited as a provider of certification services in the sense of Act No. 227/2000 Sb. Certificates issued by CESNET CA cannot be used to secure communication with the state administration. They are designed for use in national and international research projects and for applications operated by members of CESNET, a.l.e. | ||
CESNET PKI provides the following services: | CESNET PKI provides the following services: | ||
- | * [[#personal_certificates_issuance|Personal Certificates Issuance]] < | + | * [[#Personal TCS certificates|Personal TCS certificates]] |
- | * [[#server_certificates_issuance|Server Certificates Issuance]] < | + | * [[#Server TCS certificates|Server TCS certificates]] |
- | * [[#terena_server_certificates|TERENA Server Certificates]] < | + | * [[#Personal CESNET CA 4 Certificates|Personal CESNET CA 4 Certificates]] |
- | * [[#establishing_of_registration_authorities|Establishing of Registration Authorities]] < | + | * [[#Server CESNET CA 4 Certificates|Server CESNET CA 4 Certificates]] |
- | * [[#certification_of_other_certificate_authorities|Certification of other Certificate Authorities]] < | + | * [[#establishing_of_registration_authorities|Establishing of Registration Authorities]] |
+ | * [[#certification_of_other_certificate_authorities|Certification of other Certificate Authorities]] | ||
- | ===== Personal Certificates Issuance ===== | + | ===== Personal TCS certificates ===== |
- | Personal certificate issued by the CESNET PKI can be used for authentication, digital signature, and data encryption. | + | CESNET CA mediates issuance of server certificates TCS. These certificates are currently issued by [[http://www.sectigo.com|Sectigo]], whose root certificates are implicitly trusted by most internet browsers. |
- | The personal certificates validity is 13 months maximum. | + | The detailed procedure for creating a certificate application, registration and issuance of a certificate is described in the [[en:tcs-personal.html|TCS Personal Certificates manual]]. |
+ | ===== Server TCS certificates ===== | ||
- | due to capacity and organizational reasons, personal certificates can be issued only to | + | CESNET CA mediates issuance of server certificates TCS. These certificates are currently issued by [[http://www.sectigo.com|Sectigo]], whose root certificates are implicitly trusted by most internet browsers. |
- | * persons participating in CESNET's research activities, < | + | The detailed procedure for creating a certificate application, registration and issuance of a certificate is described in the [[en:st-guide-tcs-server2.html|TCS Server Certificates manual]]. |
- | * administrators of hosts and services operated by members of CESNET, a. l. e. and by insitutions participating in CESNET's research activities, and < | + | ===== Personal CESNET CA 4 Certificates ===== |
- | * CESNET employees. < | + | |
- | ===== Server Certificates Issuance ===== | + | Personal certificate issued by the CESNET PKI can be used for authentication, digital signature, and data encryption. Personal CESNET CA 4 certificates are issued with a validity of 13 months. The signature algorithm is RSA, the key length is 2048 or 4096 bits. |
- | Server certificates can be used for authenticating network hosts and services. | + | Personal CESNET CA 4 certificates can be issued to |
- | Server certificates are issued for hosts and services operated by | + | * persons participating in CESNET's research activities, |
+ | * administrators of hosts and services operated by members of CESNET, a. l. e. and by insitutions participating in CESNET's research activities, and | ||
+ | * CESNET employees. | ||
- | * institutions participating in CESNET's research activities, < | + | ===== Server CESNET CA 4 Certificates ===== |
- | * members of CESNET, a. l. e., < | + | |
- | * CESNET itself. < | + | Server certificates can be used for authenticating network hosts and services. Personal CESNET CA 4 certificates are issued with a validity of 13 months. The signature algorithm is RSA, the key length is 2048 or 4096 bits. |
+ | |||
+ | Server certificates are issued for hosts and services operated by | ||
- | ===== TERENA Server Certificates ===== | + | * institutions participating in CESNET's research activities, |
+ | * members of CESNET, a. l. e., | ||
+ | * CESNET itself. | ||
- | CESNET CA mediates issuance of server certificates TCS. These certificates are currently issued by [[http://www.comodo.com|Comod CA]], whose root certificates are implicitly trusted by most internet browsers. | ||
===== Establishing of Registration Authorities ===== | ===== Establishing of Registration Authorities ===== |