Changes

Jump to: navigation, search

CA/Required or Recommended Practices

56 bytes added, 22:18, 28 July 2009
m
CA Recommended Practices
=== Verifying Email Address Ownership/Control===
Section 7 of the [http://www.mozilla.org/projects/security/certs/policy Mozilla CA Certificate Policy ] states: “for a certificate to be used for digitally signing and/or encrypting email messages, the CA takes reasonable measures to verify that the entity submitting the request controls the email account associated with the email address referenced in the certificate”
The recommended way to satisfy this requirement is to perform a challenge-response type of procedure in which the CA sends email to the email address to be included in the certificate, and the applicant must respond in a way that proves that they have ownership/control over that email address. For instance, the CA may send an email to the address to be included in the certificate, containing secret unpredictable information, giving applicant a limited time to use the information within.
Confirm, administrator
5,526
edits

Navigation menu