CA/Revocation Reasons: Difference between revisions

Jump to navigation Jump to search
continued drafting text
(continued drafting text)
(continued drafting text)
Line 27: Line 27:
** The certificate subscriber SHOULD choose the "affiliationChanged" revocation reason when their organization's name or other organizational information in the certificate has changed.  
** The certificate subscriber SHOULD choose the "affiliationChanged" revocation reason when their organization's name or other organizational information in the certificate has changed.  
* superseded (RFC 5280 CRLReason #4)
* superseded (RFC 5280 CRLReason #4)
** The certificate subscriber SHOULD choose the "superseded" reason when they request a new certificate to replace their existing certificate.  
** The certificate subscriber SHOULD choose the "superseded" revocation reason when they request a new certificate to replace their existing certificate.  
<br>
<br>
'''NOTE:''' The following revocation reason does '''not''' need to be documented in the CA's subscriber agreement for TLS-end-entity certificates and does '''not''' need to be made available to the certificate subscriber as a revocation reason option, because the use of this reason is determined by the CA and not the subscriber.
'''NOTE:''' The following revocation reason does '''not''' need to be documented in the CA's subscriber agreement for TLS-end-entity certificates and does '''not''' need to be made available to the certificate subscriber as a revocation reason option, because the use of this reason is determined by the CA and not the subscriber.
Confirmed users, Administrators
5,526

edits

Navigation menu