
Jump to: navigation, search

CA/Required or Recommended Practices

61 bytes added, 00:40, 19 September 2019
Precertificates: add link to BR discussion
However, [ BR] section states “For purposes of clarification, a Precertificate, as described in RFC 6962 – Certificate Transparency, shall not be considered to be a “certificate” subject to the requirements of RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile under these Baseline Requirements.”
Mozilla [ interprets ] the BR language as a specific exception allowing CAs to issue a precertificate containing the same serial number as the subsequent certificate [1]. Otherwise, Mozilla infers from the existence of a precertificate that a corresponding certificate has been issued.
This means, for example, that:

Navigation menu