@@ -290,9 +290,9 @@ Licence: <a style="color: steelblue" href="
<!-- *************************************************************** -->
+<h2 id="p1">1. INTRODUCTION</h2>
+<h3 id="p1.1">1.1. Overview</h3>
This document is the Certification Practice Statement (CPS) of
@@ -304,7 +304,7 @@ including Assurers, Members, and CAcert itself.
+<h3 id="p1.2">1.2. Document name and identification</h3>
This document is the Certification Practice Statement (CPS) of CAcert.
@@ -363,7 +363,7 @@ except where explicitly deferred to.
See also <a href="#p1.5.1">1.5.1 Organisation Administering the Document</a>.
+<h3 id="p1.3">1.3. PKI participants</h3>
The CA is legally operated by CAcert Incorporated,
an Association registered in 2002 in
@@ -383,19 +383,19 @@ with the <em>Association Members</em>, which latter are
not referred to anywhere in this CPS.)
+<h4 id="p1.3.1">1.3.1. Certification authorities</h4>
CAcert does not issue certificates to external
intermediate CAs under the present CPS.
+<h4 id="p1.3.2">1.3.2. Registration authorities</h4>
Registration Authorities (RAs) are controlled under Assurance Policy
(<a href="">COD13</a>).
+<h4 id="p1.3.3">1.3.3. Subscribers</h4>
CAcert issues certificates to Members only.
@@ -403,7 +403,7 @@ Such Members then become Subscribers.
+<h4 id="p1.3.4">1.3.4. Relying parties</h4>
A relying party is a Member,
@@ -414,7 +414,7 @@ who, in the act of using a CAcert certificate,
makes a decision on the basis of that certificate.
+<h4 id="p1.3.5">1.3.5. Other participants</h4>
@@ -453,7 +453,7 @@ No other rights nor relationship is implied or offered.
+<h3 id="p1.4">1.4. Certificate usage</h3>
<p>CAcert serves as issuer of certificates for
individuals, businesses, governments, charities,
@@ -552,7 +552,7 @@ and risks, liabilities and obligations in
<div class="c figure">Table 1.4. Types of Certificate</div>
+<h4 id="p1.4.1">1.4.1. Appropriate certificate uses</h4>
General uses.
@@ -589,7 +589,7 @@ General uses.
+<h4 id="p1.4.2">1.4.2. Prohibited certificate uses</h4>
CAcert certificates are not designed, intended, or authorised for
the following applications:
@@ -603,7 +603,7 @@ the following applications:
or severe environmental damage.
+<h4 id="p1.4.3">1.4.3. Unreliable Applications</h4>
CAcert certificates are not designed nor intended for use in
@@ -639,7 +639,7 @@ for these applications:
+<h4 id="p1.4.4">1.4.4. Limited certificate uses</h4>
By contract or within a specific environment
@@ -663,7 +663,7 @@ any harm or liability caused by such usage.
policy or other external regime agreed by the parties.
+<h4 id="p1.4.5">1.4.5. Roots and Names</h4>
<strong>Named Certificates.</strong>
@@ -811,19 +811,19 @@ and will be submitted to vendors via the (Top-level) Root.
<div class="c figure">Table 1.4.5.b Certificate under Audit Roots</div>
+<h3 id="p1.5">1.5. Policy administration</h3>
<p>See <a href="#p1.2">1.2 Document Name and Identification</a>
for general scope of this document.</p>
+<h4 id="p1.5.1">1.5.1. Organization administering the document</h4>
This document is administered by the policy group of
the CAcert Community under Policy on Policy (<a href="">COD1</a>).
+<h4 id="p1.5.2">1.5.2. Contact person</h4>
For questions including about this document:
@@ -836,14 +836,14 @@ For questions including about this document:
<li>IRC: #CAcert (ssl port 7000, non-ssl port 6667)</li>
+<h4 id="p1.5.3">1.5.3. Person determining CPS suitability for the policy</h4>
This CPS and all other policy documents are managed by
the policy group, which is a group of Members of the
Community found at policy forum. See discussion forums above.
+<h4 id="p1.5.4">1.5.4. CPS approval procedures</h4>
CPS is controlled and updated according to the
Policy on Policy
@@ -862,14 +862,14 @@ The process is modelled after some elements of
the RFC process by the IETF.
+<h4 id="p1.5.5">1.5.5 CPS updates</h4>
As per above.
+<h3 id="p1.6">1.6. Definitions and acronyms</h3>
<strong><a id="d_cert">Certificate</a></strong>.
@@ -1040,10 +1040,10 @@ As per above.
<!-- *************************************************************** -->
+<h3 id="p2.1">2.1. Repositories</h3>
CAcert operates no repositories in the sense
@@ -1057,7 +1057,7 @@ there are means for Members to search, retrieve
and verify certain data about themselves and others.
+<h3 id="p2.2">2.2. Publication of certification information</h3>
CAcert publishes:
@@ -1076,24 +1076,24 @@ certificates is presumed to be public and published, once
issued and delivered to the Member.
+<h3 id="p2.3">2.3. Time or frequency of publication</h3>
Root and Intermediate Certificates and CRLs are
made available on issuance.
+<h3 id="p2.4">2.4. Access controls on repositories</h3>
<p> No stipulation. </p>
<!-- *************************************************************** -->
+<h3 id="p3.1">3.1. Naming</h3>
+<h4 id="p3.1.1">3.1.1. Types of names</h4>
<strong>Client Certificates.</strong>
@@ -1201,13 +1201,13 @@ Email addresses are verified according to
<a href="#p4.2.2">&sect;4.2.2.</a>
+<h4 id="p3.1.3">3.1.3. Anonymity or pseudonymity of subscribers</h4>
See <a href="#p1.4.5">&sect;1.4.5</a>.
+<h4 id="p3.1.4">3.1.4. Rules for interpreting various name forms</h4>
Interpretation of Names is controlled by the Assurance Policy,
is administered by means of the Member's account,
@@ -1217,7 +1217,7 @@ should be expected as fraud (e.g., phishing)
may move too quickly for policies to fully document rules.
+<h4 id="p3.1.5">3.1.5. Uniqueness of names</h4>
Uniqueness of Names within certificates is not guaranteed.
@@ -1232,7 +1232,7 @@ Domain names and email address
can only be registered to one Member.
+<h4 id="p3.1.6">3.1.6. Recognition, authentication, and role of trademarks</h4>
Organisation Assurance Policy
@@ -1243,7 +1243,7 @@ See
<a href="#p9.13">&sect;9.13</a>.
+<h4 id="p3.1.7">3.1.7. International Domain Names</h4>
Certificates containing International Domain Names, being those containing a
@@ -1476,7 +1476,7 @@ This criteria will apply to the email address and server host name fields for al
The CAcert Inc. Board has the authority to decide to add or remove accepted TLD Registrars on this list.
+<h3 id="p3.2">3.2. Initial Identity Verification</h3>
Identity verification is controlled by the
@@ -1486,7 +1486,7 @@ the following is representative and brief only.
+<h4 id="p3.2.1">3.2.1. Method to prove possession of private key</h4>
CAcert uses industry-standard techniques to
@@ -1504,7 +1504,7 @@ ActiveX uses a challenge-response protocol
to check the private key dynamically.
+<h4 id="p3.2.2">3.2.2. Authentication of Individual Identity</h4>
@@ -1591,7 +1591,7 @@ certificates that state their Assured Name(s).
+<h4 id="p3.2.3">3.2.3. Authentication of organization identity</h4>
@@ -1631,7 +1631,7 @@ stated in the OAP, briefly presented here:
+<h4 id="p3.2.4">3.2.4. Non-verified subscriber information</h4>
All information in the certificate is verified,
@@ -1639,7 +1639,7 @@ see Relying Party Statement, <a href="#p4.5.2">&sect;4.5.2</a>.
+<h4 id="p3.2.5">3.2.5. Validation of authority</h4>
The authorisation to obtain a certificate is established as follows:
@@ -1673,7 +1673,7 @@ See Organisation Assurance Policy.
+<h4 id="p3.2.6">3.2.6. Criteria for interoperation</h4>
CAcert does not currently issue certificates to subordinate CAs
@@ -1682,13 +1682,13 @@ Other CAs may become Members, and are then subject to the
same reliance provisions as all Members.
+<h3 id="p3.3">3.3. Re-key Requests</h3>
Via the Member's account.
+<h3 id="p3.4">3.4. Revocations Requests</h3>
Via the Member's account.
@@ -1701,7 +1701,7 @@ process or file a dispute.
<!-- *************************************************************** -->
The general life-cycle for a new certificate for an Individual Member is:</p>
@@ -1732,16 +1732,16 @@ The general life-cycle for a new certificate for an Individual Member is:</p>
+<h3 id="p4.1">4.1. Certificate Application</h3>
+<h4 id="p4.1.1">4.1.1. Who can submit a certificate application</h4>
Members may submit certificate applications.
On issuance of certificates, Members become Subscribers.
+<h4 id="p4.1.2">4.1.2. Adding Addresses</h4>
The Member can claim ownership or authorised control of
@@ -1760,7 +1760,7 @@ There are these controls:</p>
+<h4 id="p4.1.3">4.1.3. Preparing CSR </h4>
Members generate their own key-pairs.
@@ -1775,7 +1775,7 @@ The Certificate Signing Request (CSR) is prepared by the
Member for presentation to the automated system.
+<h3 id="p4.2">4.2. Certificate application processing</h3>
The CA's certificate application process is completely automated.
@@ -1788,7 +1788,7 @@ purpose, the requirements for each purpose must be
+<h4 id="p4.2.1">4.2.1. Authentication </h4>
The Member logs in to her account on the CAcert website
@@ -1796,7 +1796,7 @@ fulfilled.
and passphrase or with her CAcert client-side digital certificate.
+<h4 id="p4.2.2">4.2.2. Verifying Control</h4>
In principle, at least two controls are placed on each address.
@@ -1879,7 +1879,7 @@ Notes.</p>
+<h4 id="p4.2.3">4.2.3. Options Available</h4>
The Member has options available:
@@ -1902,7 +1902,7 @@ The Member has options available:
+<h4 id="p4.2.4">4.2.4. Client Certificate Procedures</h4>
For an individual client certificate, the following is required.</p>
@@ -1918,7 +1918,7 @@ For an individual client certificate, the following is required.</p>
+<h4 id="p4.2.5">4.2.5. Server Certificate Procedures</h4>
For a server certificate, the following is required:</p>
@@ -1933,14 +1933,14 @@ For a server certificate, the following is required:</p>
+<h4 id="p4.2.6">4.2.6. Code-signing Certificate Procedures</h4>
Code-signing certificates are made available to Assurers only.
They are processed in a similar manner to client certificates.
+<h4 id="p4.2.7">4.2.7. Organisation Domain Verification</h4>
Organisation Domains are handled under the Organisation Assurance Policy
@@ -1948,9 +1948,9 @@ and the Organisation Handbook.
+<h3 id="p4.3">4.3. Certificate issuance</h3>
+<h4 id="p4.3.1">4.3.1. CA actions during certificate issuance</h4>
<strong>Key Sizes.</strong>
@@ -2047,7 +2047,7 @@ algorithm following the process:
<div class="c figure">Table 4.3.1. Permitted Data in Signed OpenPgp Keys</div>
+<h4 id="p4.3.2">4.3.2. Notification to subscriber by the CA of issuance of certificate</h4>
Once signed, the certificate is
@@ -3493,7 +3493,7 @@ and takes privacy more seriously.
Any privacy issue may be referred to dispute resolution.
+<h4 id="p9.4.5">9.4.5. Notice and consent to use private information</h4>
Members are permitted to rely on certificates of other Members.
As a direct consequence of the general right to rely,