18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Systems using high-hardware assurance certificates shall store Trusted <strong>Certificate</strong>s such that<br />

unauthorized alteration or replacement is readily detectable.<br />

6.1.5 <strong>Key</strong> Sizes<br />

If the RPMA determines that the security of a particular algorithm may be compromised, it may<br />

require the CAs to revoke the affected certificates. All certificates and Transport Layer Security<br />

(TLS) protocols shall use the following algorithm suites.<br />

<strong>Public</strong> <strong>Key</strong>s:<br />

Cryptographic<br />

Function<br />

<strong>Public</strong> keys in CA,<br />

Identity,<br />

Authentication, and<br />

Digital Signature<br />

<strong>Certificate</strong>s; CRL<br />

Signatures; and OCSP<br />

Response Signatures<br />

(FIPS 186-3)<br />

<strong>Public</strong> <strong>Key</strong>s in<br />

Encryption <strong>Certificate</strong>s<br />

(PKCS 1 for RSA and<br />

NIST SP 800-56A for<br />

ECDH)<br />

Expire on or<br />

before 12/31/2010<br />

1024 bit RSA, 193<br />

bit ECDSA in prime<br />

field or 163 bit<br />

ECDSA in binary<br />

field<br />

1024 bit, 193 bit<br />

ECDSA in prime<br />

field or 163 bit<br />

ECDSA in binary<br />

field<br />

Expire after<br />

12/31/2010 but<br />

before 12/31/2030<br />

2048 bit RSA ,224<br />

bit ECDSA in prime<br />

field or 233 bit<br />

ECDSA in binary<br />

field<br />

2048 bit, 224 bit<br />

ECDSA in prime<br />

field or 233 bit<br />

ECDSA in binary<br />

field<br />

Symmetric Encryption AES AES AES<br />

Expire after<br />

12/31/2030<br />

3072 bit RSA, 256<br />

bit ECDSA in prime<br />

field, or 283 bit<br />

ECDSA in binary<br />

field<br />

3072 bit RSA, 256<br />

bit ECDSA in prime<br />

field, or 283 bit<br />

ECDSA in binary<br />

field<br />

60 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!