18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

11 <strong>PKI</strong> REPOSITORY INTEROPERABILITY PROFILE<br />

This section provides an overview of the <strong>PKI</strong> Repository interoperability profiles. The following<br />

topics are discussed:<br />

� Protocol<br />

� Authentication<br />

� Naming<br />

� Object Class<br />

� Attributes<br />

Each of these items is described below.<br />

11.1 Protocol<br />

The <strong>Raytheon</strong> <strong>PKI</strong> Repository shall provide HTTP protocol access to certificates and CRLs.<br />

11.2 Authentication<br />

The <strong>Raytheon</strong> <strong>PKI</strong> Repository shall permit “none” (anonymous) authentication to read certificate<br />

and CRL information.<br />

<strong>Raytheon</strong> shall be free to implement authentication mechanisms of its choice for browse and list<br />

operations.<br />

For the external <strong>PKI</strong> Directory used for interoperability, any write, update, add entry, delete<br />

entry, add attribute, delete attribute, change schema etc, shall require password over SSL or<br />

stronger authentication mechanism.<br />

11.3 Naming<br />

This CP has defined the naming convention.<br />

When a LDAP repository is used:<br />

1. <strong>Certificate</strong>s shall be stored in the <strong>Raytheon</strong> LDAP Repository in the entry that appears in<br />

the certificate subject name.<br />

2. issuedByThisCA element of crossCross<strong>Certificate</strong>Pair shall contain the certificate(s) issued<br />

by a CA whose name the entry represents; and<br />

3. CRLs shall be stored in the <strong>Raytheon</strong> <strong>PKI</strong> Repository in the entry that appears in the CRL<br />

issuer name.<br />

11.4 Object Class<br />

When a LDAP repository is used:<br />

1. Entries that describe CAs shall be defined by organizationUnit structural object class.<br />

These entries shall also be a member of pkiCA cpCPS auxiliary object classes; and<br />

109 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!