18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.3.1 CA Actions during <strong>Certificate</strong> Issuance<br />

A CA verifies the source of a certificate request before issuance. <strong>Certificate</strong>s shall be checked<br />

to ensure that all fields and extensions are properly populated. After generation, verification, and<br />

acceptance, a CA shall post the certificate as set forth in this CP.<br />

4.3.2 Notification to Subscriber of <strong>Certificate</strong> Issuance<br />

A CA shall notify a subject (CA or Subscriber) of certificate issuance.<br />

4.4 <strong>Certificate</strong> Acceptance<br />

The MOA shall set forth responsibilities of all parties before the RPMA authorizes issuance of a<br />

cross certificate by a <strong>Raytheon</strong> CA. Once a CA certificate has been issued, its acceptance by<br />

the subject shall trigger the Subject CA's obligations under the MOA (if any) and this CP.<br />

4.4.1 Conduct Constituting <strong>Certificate</strong> Acceptance<br />

For CAs cross certified with <strong>Raytheon</strong>, certificate acceptance shall be governed by the MOA<br />

between <strong>Raytheon</strong> and the representatives of the Cross-certified CA.<br />

For <strong>Raytheon</strong> CAs operating under this policy, notification to the CA shall constitute acceptance,<br />

unless the CA objects. In the case of objection, the certificate shall be revoked.<br />

For end-entities, downloading of the certificate shall constitute acceptance of the issued<br />

certificate.<br />

4.4.2 <strong>Public</strong>ation of the <strong>Certificate</strong> by the CA<br />

CA certificates and Subscriber certificates shall be published to the appropriate repositories.<br />

4.4.3 Notification of <strong>Certificate</strong> Issuance by the CA to Other Entities<br />

The ROA shall inform the RPMA of any CA certificate issued by the <strong>Raytheon</strong> <strong>PKI</strong>.<br />

When the <strong>Raytheon</strong> Root CA issues a CA certification, the RPMA shall inform the CertiPath<br />

PMA of successful certification issuance.<br />

Notification of cross certificate issuance by the <strong>Raytheon</strong> Root CA shall be provided to all crosscertified<br />

entities.<br />

4.5 <strong>Key</strong> Pair and <strong>Certificate</strong> Usage<br />

4.5.1 Subscriber Private <strong>Key</strong> and <strong>Certificate</strong> Usage<br />

Subscribers and CAs shall protect their private keys from access by any other party.<br />

Subscribers and CAs shall use their private keys for the purposes as constrained by the<br />

extensions (such as key usage, extended key usage, certificate policies, etc.) in the certificates<br />

issued to them.<br />

4.5.2 Relying Party <strong>Public</strong> <strong>Key</strong> and <strong>Certificate</strong> Usage<br />

Relying parties shall use public key certificates for the purposes as constrained by the<br />

extensions (such as key usage, extended key usage, certificate policies, etc.) in the certificates.<br />

4.6 <strong>Certificate</strong> Renewal<br />

<strong>Raytheon</strong> does not support certificate renewal.<br />

33 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!