18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.8.5 Conduct Constituting Acceptance of Modified <strong>Certificate</strong><br />

See Section 4.4.1.<br />

4.8.6 <strong>Public</strong>ation of the Modified <strong>Certificate</strong> by the CA<br />

See Section 4.4.2.<br />

4.8.7 Notification of <strong>Certificate</strong> Issuance by the CA to Other Entities<br />

See Section 4.4.3.<br />

4.9 <strong>Certificate</strong> Revocation and Suspension<br />

Revocation requests must be authenticated. Requests to revoke a certificate may be<br />

authenticated using that certificate's associated public key, regardless of whether or not the<br />

private key has been compromised.<br />

4.9.1 Circumstance for Revocation of a <strong>Certificate</strong><br />

A certificate shall be revoked when the binding between the subject and the subject’s public key<br />

defined within a certificate is no longer considered valid. Examples of circumstances that<br />

invalidate the binding are:<br />

� Identifying information or affiliation components of any names in the certificate<br />

become invalid;<br />

� Privilege attributes asserted in the Subject's certificate are reduced;<br />

� The Subject can be shown to have violated the stipulations of its agreement;<br />

� The private key is suspected of compromise; or<br />

� The Subject or other authorized party (as defined in the applicable CP or CPS) asks<br />

for his/her certificate to be revoked.<br />

Whenever any of the above circumstances occur, the associated certificate shall be revoked<br />

and placed on the CRL. Revoked certificates shall be included on all new publications of the<br />

certificate status information until at least the certificates expire.<br />

The <strong>Raytheon</strong> <strong>PKI</strong> shall request the CBCA revoke their cross-certificate if they do not meet the<br />

stipulations of the certificate policies listed in their certificate, including all OIDs asserted in this<br />

CP.<br />

4.9.2 Who Can Request Revocation of a <strong>Certificate</strong><br />

A certificate subject, human supervisor of a human subject, Human Resources (HR) person for<br />

the human subject, security officer for the human subject, <strong>PKI</strong> Sponsor for a device, Signing CA,<br />

or RA may request revocation of a certificate.<br />

In the case of certificates issued by a <strong>Raytheon</strong> CA, the RPMA may request revocation of a<br />

certificate.<br />

For CA certificates, authorized individuals representing the CA operations may request<br />

revocation of certificates.<br />

4.9.3 Procedure for Revocation Request<br />

A request to revoke a certificate shall identify the certificate to be revoked, explain the reason<br />

for revocation, and allow the request to be authenticated (e.g., digitally or manually signed).<br />

36 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!