Changes

Jump to: navigation, search

CA/Required or Recommended Practices

No change in size, 01:58, 5 February 2009
Changed "suspect" to "invalid" in revocation practice
* A hierarchical structure of a single root with intermediate certs (subroots) is preferred. The single top-level root's public certificate is supplied for Mozilla's root list; the subroots are not. See [[CA:Recommendations_for_Roots]]
* CAs should revoke certificates with private keys that are known to be compromised, or for which verification of subscriber information is known to be suspectinvalid.
==== Notes for future work ====
Confirm
610
edits

Navigation menu