Confirmed users, Administrators
5,526
edits
m (→Disable a Root) |
m (→Disable a Root) |
||
| Line 46: | Line 46: | ||
Reasons for disabling a root certificate may include, but are not limited to: | Reasons for disabling a root certificate may include, but are not limited to: | ||
* Expired or Expiring CA | * Expired or Expiring CA | ||
* Small modulus key length [http://csrc.nist.gov/groups/ST/key_mgmt/documents/Transitioning_CryptoAlgos_070209.pdf NIST | * Small modulus key length; [http://csrc.nist.gov/groups/ST/key_mgmt/documents/Transitioning_CryptoAlgos_070209.pdf NIST recommendations about phasing out 1024 bit roots] | ||
* Outdated signing key algorithm | * Outdated signing key algorithm; e.g. MD2/MD5 | ||
* Transition/Rollover to new root completed | * Transition/Rollover to new root completed | ||
* Legacy, no longer in use | * Legacy, no longer in use | ||