Steve and Jeff:
We are about to install and put in operation our COST PCA
supporting Low Level Assurance Certification Policy.
Within our internal implementation, we believe,
it is fully compliant with the RFC 1422. However, as you know,
in order to run PCA, we also need cooperation with IPRA,
as described in RFC 1422.
So, would you please be so kind and inform us how are currently IPRA
functions implemented, in particular:
1.) What is the procedure for certification of PCAs ?
2.) How can we file our Security Policy with IPRA
(as required in section 3.4.2.1) ?
3.) Are there any fees to IPRA ?
4.) How IPRA ensures the uniqueness of DNs
(section 3.4.2.2) ?
5.) How is maintenance and distribution of CRLs performed
by IPRA (section 3.4.2.5) ?
Thank you in advance for your help and information.
Regards,
Sead Muftic
COST Computer Security Technologies AB
Stockholm, Sweden