Structures
 
Membership 
Contact us 
 
  IGTF 
APGridPMA 
TAGPMA 
REFEDS 
SCI 
WISE 
 Documents
 
Charter 
Guidelines 
One Statement Policies 
 
CAOPS-WG 
Wiki 
 Technical Info
 
CA Distribution download 
Subject Locator 
Find your local CA 
About your certificate 
 
Newsletter issues 
Subscribe 
Service notices 
 
Tools download and fetch-crl 
Technical documentation 
IGTF OID Registry 
SHA-2 timeline 
 Meetings
 
Karlsruhe, DE, October 1-3, 2025 
Prague, CZ, May 14-16, 2025 
 
Overview 
Agendas 
Intranet and Reviews   
   
  
   | 
Guidelines and Authentication Profiles: Classic X.509 CAs with secured infrastructure
- Classic X.509 CAs with secured infrastructure
 
  Formats available: 
  Adobe PDF;
  Microsoft Word;
   
  Managed by: EUGridPMA
   
  Status: version 5.0, endorsed EUGridPMA, pending TAG, AP
  
  This is an Authentication Profile of the International Grid Trust Federation
  describing the minimum requirements on traditional X.509 PKI CAs. Traditional
  X.509 Public Key Certification Authorities (traditional PKI CAs) issue
  long-term credentials to end-entities, who will themselves posses and control
  their key pair and their activation data. These CAs act as an independent
  trusted third party for both subscribers and relying parties within the
  infrastructure. These authorities will use a long-term signing key, which is
  stored in a secure manner as defined in the Profile.
   
 Note that all technology-specific authentication profiles have been amalgamated into a common Authentication Assurance guidelines, augmented with PKIX technology-specific guidelines. The IGTF Authentication Assurance profile corresponding to Classic is https://igtf.net/ap/authn-assurance/cedar. Assurance Profiles are registered with IANA under RFC6711.
 
  Relevant necessary documents:
  
  
  Version history:
   
  
  Associated documents
   
   
 
 
  Comments to David Groep. This site is hosted at Nikhef, subject to the privacy policy.
   |