Asia Pacific Grid Minimum CA Requirements

version 1.2
July 4, 2006

1 Introduction

The Asia Pacific Grid Policy Management Authority (hereafter called APGrid PMA) provides the minimum requirements for traditional online PKI CAs. The PMA specifies two levels of the minimum requirements, one is for experimental CAs and the other is for production CAs. An experimental CA is considered as an alternative of the Globus CA and it will be accepted within Asia for experimental use. For production runs and international collaboration, any CA must satisfy the minimum requirements for production CAs.

In this document, the key words "must", "must not", "required", "shall", "shall not", "should", "should not", "recommended", "may", and "optional" are to be interpreted as described in RFC 2119.

The minimum requirements for Production CA are based on "Profile for Traditional X.509 Public Key Certification Authorities with secured infrastructure Version 4.0" which is an Authentication Profile of the International Grid Trust Federation describing the minimum requirements on traditional X.509 PKI CAs. The Authentication Profile is managed by the European Grid Policy Management Authority and available from the EUGrid PMA web site at:

2 Minimum CA Requirements for Production CA

2.1 Certification Authority


2. CA System

3. CA Key

4. CA Certificate

5. CA Namespace

6. Certificate Revocation

7. Certificate Revocation List (CRL)

8. End Entity Certificates and keys

9. Records Archival

10. Audits

11. Publication and Repository responsibilities

12. Privacy and confidentiality

13. Compromise and disaster recovery

2.2 Registration Authority

1. Entity Identification

2. Name Uniqueness

3. RA to CA communications

4. Records and Archival

3 Minimum CA Requirements for Experimental CA

3.1 Certification Authority

1. CA System

2. CA Key

3. CA Certificate

4. CA Namespace

5. Certificate Revocation

6. Certificate Revocation List (CRL)

7. End Entity Certificates and keys

3.2 Registration Authority

1. Entity Identification

2. Name Uniqueness