CA/Required or Recommended Practices: Difference between revisions

→‎CA Hierarchy: Removed broken link
(Added CPS review of Identrust)
(→‎CA Hierarchy: Removed broken link)
Line 210: Line 210:
=== CA Hierarchy ===
=== CA Hierarchy ===


A hierarchical structure of a single root with intermediate certs (subroots) is preferred.  The single top-level root's public certificate is supplied for Mozilla's root list;  the subroots are not.  See [[CA:Recommendations_for_Roots]].
A hierarchical structure of a single root with intermediate certs (subroots) is preferred.  The single top-level root's public certificate is supplied for Mozilla's root list;  the subroots are not.  


CAs that issue certificates under multiple subordinate CAs (i.e., under a  root CA whose CA certificate is being requested for inclusion) or under multiple CA hierarchies (i.e., rooted at multiple root CAs, one or more of whose certificates is being requested for inclusion) should provide additional information as noted:
CAs that issue certificates under multiple subordinate CAs (i.e., under a  root CA whose CA certificate is being requested for inclusion) or under multiple CA hierarchies (i.e., rooted at multiple root CAs, one or more of whose certificates is being requested for inclusion) should provide additional information as noted:
Confirmed users
377

edits