Changes

Jump to: navigation, search

CA/Forbidden or Problematic Practices

152 bytes added, 23:29, 25 October 2018
updated referenced section numbers and quotes
=== Certificates Referencing Local Names or Private IP Addresses ===
This is forbidden by Section 7.1.4.2.1 of the Baseline Requirements. [httphttps://www.cabforum.org/baseline-requirements-documents.html BR 9.2.1/ Baseline Requirements], which says: “As * As of the Effective Date of these Requirements, prior to the issuance of a Certificate with a subjectAlternativeName (SAN) extension or Subject Common Name commonName field containing a Reserved IP Address or Internal Server Name, the CA shall SHALL notify the Applicant that the '''use of such Certificates has been deprecated by the CA / Browser Forum and that the practice will be eliminated by October 2016'''. Also as of the Effective Date, the CA shall not SHALL NOT issue a certificate with an Expiry Date later than 1 November 2015 with a SAN subjectAlternativeName extension or Subject Common Name commonName field containing a Reserved IP Address or Internal Server Name. As from Effective 1 October 2016, CAs shall SHALL revoke all unexpired Certificateswhose subjectAlternativeName extension or Subject commonName field contains a Reserved IP Address or Internal Name.
=== Issuing SSL Certificates for .int Domains ===
Confirm, administrator
5,526
edits

Navigation menu