18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

If a RA signature keys are compromised, lost, or suspected to be compromised:<br />

1. The RA certificate shall be immediately revoked;<br />

2. A new RA key pair shall be generated in accordance with procedures set forth in the<br />

applicable CPS;<br />

3. New RA certificate shall be requested in accordance with the initial registration process<br />

as described in section 3.2;<br />

4. All certificate registration requests approved by the RA since the date of the suspected<br />

compromise shall be reviewed to determine which one are legitimate;<br />

5. For those certificates requests or approval than can not be ascertained as legitimate, the<br />

resultant certificates shall be revoked and their subjects (i.e., subscribers) shall be<br />

notified of revocation.<br />

5.7.4 Business Continuity Capabilities after a Disaster<br />

In the case of a disaster whereby a CA installation is physically damaged and all copies of the<br />

CA Signing <strong>Key</strong> are destroyed as a result, the CA shall request that its certificates be revoked.<br />

The CA shall follow steps 2 through 5 in Section 5.7.3 above.<br />

The <strong>PKI</strong> Repositories containing certificates and certificate status information shall be deployed<br />

so as to provide 24 hour per day/365 day per year availability. <strong>Raytheon</strong> shall implement<br />

features to provide high levels of <strong>PKI</strong> Repository reliability.<br />

5.8 CA, CSA, and RA Termination<br />

In the event of termination of a CA, the CA shall request all certificates issued to it be revoked.<br />

In the event of a CA termination, <strong>Raytheon</strong> shall provide as much advance notice as<br />

circumstances permit notice to all cross certified CAs prior to the termination.<br />

A CA, CSA, and RA shall archive all audit logs and other records prior to termination.<br />

A CA, CSA, and RA shall destroy all its private keys upon termination.<br />

CA, CSA, and RA archive records shall be transferred to an appropriate authority such as the<br />

RPMA responsible for the entity.<br />

If a Root CA is terminated, the Root CA shall use secure means to notify the subscribers to<br />

delete all trust anchors representing the CA.<br />

57 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!