CA/Subordinate CA Checklist
< CA
Jump to navigation
Jump to search
Subordinate CAs Operated by Third Parties For Internal Use
When your root signs subordinate CAs for enterprises/companies who operate the sub-CA for their own use, the following information needs to be provided and publicly available.
- General description of the sub-CAs operated by third parties.
- The CP/CPS that the sub-CAs are required to follow.
- Requirements (technical and contractual) for sub-CAs in regards to whether or not sub-CAs are constrained to issue certificates only within certain domains, and whether or not sub-CAs can create their own subordinates.
- Requirements (typically in the CP or CPS) for sub-CAs to take reasonable measures to verify the ownership of the domain name and email address for end-entity certificates chaining up to the root, as per section 7 of our Mozilla CA certificate policy.
- domain ownership/control
- email address ownership/control
- digitally signing code objects -- entity submitting the certificate signing request is the same entity referenced in the certificate
- Description of audit requirements for sub-CAs (typically in the CP or CPS)
- Whether or not the root CA audit includes the sub-CAs.
- Who can perform the audits for sub-CAs.
- Frequency of the audits for sub-CAs.
Subordinate CAs Operated by Third Parties For External Use
This section applies when your root signs subordinate CAs for companies who use the sub-CA to sign other sub-CAs or certificates for other companies or individuals not affiliated with their company. For instance, this section applies to you if your root issues sub-CAs that are used by Certificate Service Providers (CSP).
In addition to the information listed above, you will also need to provide the following information for each CSP.
- Sub-CA Company Name
- Sub-CA Corporate URL
- Sub-CA cert download URL
- General CA hierarchy under the sub-CA.
- Sub-CA CP/CPS Links
- The section numbers and text (in English) in the CP/CPS that demonstrate that reasonable measures are taken to verify the ownership of the domain name and email address for end-entity certificates chaining up to the root, as per section 7 of our Mozilla CA certificate policy.
- domain ownership/control
- email address ownership/control
- digitally signing code objects -- entity submitting the certificate signing request is the same entity referenced in the certificate
- Identify if the SSL certificates chaining up to the sub-CA are DV and/or OV. Some of the potentially problematic practices, only apply to DV certificates.
- DV: Organization attribute is not verified. Only the Domain Name referenced in the certificate is verified to be owned/controlled by the subscriber.
- OV: Both the Organization and the ownership/control of the Domain Name are verified.
- Review the CP/CPS for Potentially Problematic Practices. Provide further info when a potentially problematic practice is found.
- If the root CA audit does not include this sub-CA, then for this sub-CA provide a publishable statement or letter from an auditor that meets the requirements of sections 8, 9, and 10 of our Mozilla CA certificate policy.
- Provide information about the CRL update frequency for end-entity certificates. There should be a statement in the CP/CPS that the sub-CA must follow to the effect that the CRL for end-entity certs is updated whenever a cert is revoked, and at least every 24 or 36 hours.
- If this sub-CA provides OCSP, then a test must be done to make sure that their OCSP responder works within the Firefox browser. Provide the url to a website whose SSL cert chains up to this sub-CA and has the AIA extension referencing the OCSP responder. The Mozilla representative will perform the following check:
- Enforce OCSP in Firefox: Tools->Options…->Advanced->Encryption->Validation
- Select the box for “When an OCSP server connection fails, treat the certificate as invalid”
- Browse to the given url. Ensure that the website loads without error into Firefox, and that it's SSL cert chains up to the sub-CA and references the OCSP responder in the AIA extension.