18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.6.1 Circumstance for <strong>Certificate</strong> Renewal<br />

Not applicable.<br />

4.6.2 Who may Request Renewal<br />

Not applicable.<br />

4.6.3 Processing <strong>Certificate</strong> Renewal Requests<br />

Not applicable.<br />

4.6.4 Notification of New <strong>Certificate</strong> Issuance to Subscriber<br />

Not applicable.<br />

4.6.5 Conduct Constituting Acceptance of a Renewal <strong>Certificate</strong><br />

Not applicable.<br />

4.6.6 <strong>Public</strong>ation of the Renewal <strong>Certificate</strong> by the CA<br />

Not applicable.<br />

4.6.7 Notification of <strong>Certificate</strong> Issuance by the CA to Other Entities<br />

Not applicable.<br />

4.7 <strong>Certificate</strong> Re-<strong>Key</strong><br />

The longer and more often a key is used, the more susceptible it is to loss or discovery.<br />

Therefore, it is important that a Subscriber periodically obtains new keys and reestablishes its<br />

identity. Re-keying a certificate means that a new certificate is created that has the same<br />

characteristics and level as the old one, except that the new certificate has a new, different<br />

public key (corresponding to a new, different private key) and a different serial number, and it<br />

may be assigned a different validity period.<br />

4.7.1 Circumstance for <strong>Certificate</strong> Re-key<br />

A CA may issue a new certificate to the Subject when the Subject has generated a new key pair<br />

and is entitled to a certificate.<br />

4.7.2 Who may Request Certification of a New <strong>Public</strong> <strong>Key</strong><br />

A Subject may request the re-key of its certificate.<br />

A <strong>PKI</strong> Sponsor may request re-key of a component certificate.<br />

4.7.3 Processing <strong>Certificate</strong> Re-keying Requests<br />

A certificate re-key shall be achieved using one of the following processes:<br />

� Initial registration process as described in Section 3.2; or<br />

� Identification & Authentication for Re-key as described in Section 3.3.<br />

For cross certificates issued by a <strong>Raytheon</strong> CA, certificate re-key also requires that a valid MOA<br />

exists between <strong>Raytheon</strong> and the cross certified <strong>PKI</strong>, and the term of the MOA is beyond the<br />

expiry period for the new certificate.<br />

34 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!