Changes

Jump to: navigation, search

CA/Revocation Reasons

30 bytes added, 18:37, 13 April 2022
Incorporating feedback
Section 6.1.1 of Mozilla's Root Store Policy (starting with version 2.8) requires that the Subscriber Agreement or Terms of Use for TLS end-entity certificates inform certificate subscribers about the following revocation reasons. The Subscriber Agreement or Terms of Use MUST contain provisions imposing on the Applicant itself (or made by the Applicant on behalf of its principal or agent under a subcontractor or hosting service relationship) an obligation and warranty to specify the following revocation reasons when they are applicable to the reason that the subscriber is requesting that their certificate be revoked.
* No reason provided or unspecified (RFC 5280 CRLReason #0)
** When the reason codes below do not apply to the revocation request, the certificate may be revoked with an unspecified reason.
* keyCompromise (RFC 5280 CRLReason #1)
** The certificate subscriber MUST choose the "keyCompromise" revocation reason when they become aware of or have reason to believe that the private key of their certificate has been compromised, e.g. an unauthorized person has had access to the private key of their certificate.
* cessationOfOperation (RFC 5280 CRLReason #5)
** The certificate subscriber SHOULD choose the "cessationOfOperation" revocation reason when they no longer own all of the domain names in the certificate or when they will no longer be using the certificate because they are discontinuing their website.
* affiliationChanged (RFC 5280 CRLReason #3)
** The certificate subscriber SHOULD choose the "affiliationChanged" revocation reason when their organization's name or other organizational information in the certificate has changed.
* superseded (RFC 5280 CRLReason #4)
** The certificate subscriber SHOULD choose the "superseded" revocation reason when they request a new certificate to replace their existing certificate.
* No reason providedcessationOfOperation (RFC 5280 CRLReason #5)** When The certificate subscriber SHOULD choose the above "cessationOfOperation" revocation reason codes do not apply to when they no longer own all of the domain names in the revocation request, certificate or when they will no longer be using the certificate subscriber SHOULD NOT indicate a revocation reasonbecause they are discontinuing their website.
Section 7.2.2 of the [https://cabforum.org/baseline-requirements-documents/ CA Browser Forum Baseline Requirements] says:
Confirm, administrator
5,526
edits

Navigation menu