Confirmed users, Administrators
5,526
edits
Line 111: | Line 111: | ||
* BR Appendix A for root and intermediate certs - Cryptographic Algorithm and Key Requirements (Normative) - Certificates MUST meet the following requirements for algorithm type and key size. | * BR Appendix A for root and intermediate certs - Cryptographic Algorithm and Key Requirements (Normative) - Certificates MUST meet the following requirements for algorithm type and key size. | ||
* BR Appendix B for root and intermediate certs – Certificate Extensions (Normative) - This appendix specifies the requirements for Certificate extensions for Certificates generated after the Effective Date. | * BR Appendix B for root and intermediate certs – Certificate Extensions (Normative) - This appendix specifies the requirements for Certificate extensions for Certificates generated after the Effective Date. | ||
* | * With regards to root and intermediate certificates, the items listed in section 4 of [https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/inclusion/ Mozilla CA Certificate Inclusion Policy]: | ||
** ASN.1 DER encoding errors; | ** ASN.1 DER encoding errors; | ||
** invalid public keys (e.g., RSA certificates with public exponent equal to 1); | ** invalid public keys (e.g., RSA certificates with public exponent equal to 1); |