GSA / GSA/fpkilint

Common Profiles - CA certificate profiles - Subject Distinguished Names

Open
#80 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
16
Forks
14
PR merge metrics
No merged PRs in 30d

Description

Common SSP profiles for self-signed, self-issued, cross-certificates, and intermediate CA certificates are configured to require O=U.S. Government, and will throw failures if other commercial names are asserted. This logic on subjectDN allowance should also apply to the PIV content signing certificate profile.

Since Commercial SSPs are not U.S. Government entities, they should have a similar allowance to assert O="Company name".... the code required for this allowance should be available in the subject field of the associated Federal Bridge certificate profiles for these 4 certificate types.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by comparing the subject fields in the Federal Bridge certificate profiles for self-signed, self-issued, cross-certificate, and intermediate CA certificates. Trace how their subjectDN allowances are applied to the PIV content signing certificate profile and determine the corresponding Commercial SSP behavior. Done means commercial profiles accept a company name while the existing U.S. Government requirement remains for applicable Common SSP profiles.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
cryptography, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.