Published on 29 January 2025
PKI Glossary
This online PKI glossary offers a collection of terms and definitions related to Public Key Infrastructure (PKI).
Note: The glossary is currently under construction and will be continuously expanded and improved to provide a valuable source of information.
A
Definition
A pass-phrase, personal identification number (PIN), biometric data, or other mechanisms of equivalent authentication robustness used to protect access to any use of a private key, except for private keys associated with System or Device certificates.
Source: https://csrc.nist.gov/glossary/term/activation_dataTranslations
Definition
(See Swiss Government PKI)
Former name of the Swiss Government PKI. It is often still used as a synonym.Link
Translations
Definition
In accordance with the Ordinance on the Federal Identity Management Systems and Directory Services (OIAM), the «Admin Directory» includes information on persons, information on the relationship between the persons and the federal government, contact details, information on organizational units, roles and premises within the federal administration. It also includes the storage of digital certificates for the employees of the federal administration and the cantons.
Translations
Definition
A corporation, partnership, joint venture or other entity controlling, controlled by, or under common control with another entity, or an agency, department, political subdivision, or any entity operating under the direct control of a Government Entity.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
The natural person or Legal Entity that applies for (or seeks renewal of) a Certificate. Once the Certificate is issued, the Applicant is referred to as the Subscriber. For Certificates issued to devices, the Applicant is the entity that controls or operates the device named in the Certificate, even if the device is sending the actual certificate request.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A natural person or human sponsor who is either the Applicant, employed by the Applicant, or an authorized agent who has express authority to represent the Applicant:
- who signs and submits, or approves a certificate request on behalf of the Applicant, and/or
- who signs and submits a Subscriber Agreement on behalf of the Applicant, and/or
- who acknowledges the Terms of Use on behalf of the Applicant when the Applicant is an Affiliate of the CA or is the CA.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/
Translations
Definition
A supplier of Internet browser software or other relying-party application software that displays or uses Certificates and incorporates Root Certificates.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A letter attesting that Subject Information is correct written by an accountant, lawyer, government official, or other reliable third party customarily relied upon for such information.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A report from a Qualified Auditor stating the Qualified Auditor’s opinion on whether an entity’s processes and controls comply with the mandatory provisions of these Requirements.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Person who assesses conformity to requirements as specified in given requirements documents.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Translations
Definition
A natural person or Legal Entity that meets the requirements of Section 8.2.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
B
C
Definition
Public key of a user, together with some other information, rendered un-forgeable by encipherment with the private key of the certification authority which issued it.
Note: See ISO/IEC 9594-8/Recommendation ITU-T X.509.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Translations
Definition
Authority trusted by one or more users to create and assign certificates.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
CA
Translations
Definition
Revocation list containing a list of CA-certificates issued to certification authorities that have been revoked by the certificate issuer.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
CARL
Translations
Definition
The quality class of all SG-PKI certificates issued is described by their designation, class A to E. Each class must fulfill the applicable guidelines (ZertES, ETSI, etc.). These are regularly checked by internal and external audits.
Translations
Definition
The Manager of the certificate.
Translations
Definition
The person (administrative unit, organization) who owns the certificate.
Translations
Definition
Processes, practices, and procedures associated with the use of keys, software, and hardware, by which the CA verifies Certificate Data, issues Certificates, maintains a Repository, and revokes Certificates.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Certificate Policy (CP): named set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
CP
Link
Translations
Definition
Certification Practice Statement (CPS): statement of the practices which a Certification Authority employs in issuing managing, revoking, and renewing or re-keying certificates.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
CPS
Link
Translations
Definition
Complaint of suspected Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, or inappropriate conduct related to Certificates.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
In SG-PKI scope: Certificate Renewal is a process where a Subscriber automatically obtains a new certificate, if proof of key possession of the current, valid certificate can be provided. The renewed certificate contains new validity information, the next prestaged key pairs but retains the same Common Name.
Link
Translations
Definition
Signed list indicating a set of certificates that have been revoked by the certificate issuer.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
CRL
Link
Translations
Definition
Certificate Service Provider: an organisation that operates a PKI infrastructure, e.g. the Swiss Government PKI. A CSP can be part of a TSP or be independent.
Acronym
CSP
Translations
Definition
Certificate users are persons or organizations that use a certificate of an owner. Certificate users can also be, for example, organizational units of the federal administration, natural persons, an IT system, an application or participants of another PKI.
Translations
Definition
Certificates of type “Class A” issued by SG-PKI are certificates as defined by the Swiss law on digital signatures ZertES. Specifically qualified signature certificates and regulated authority certificates (Behördenzertifikate)
Link
Translations
Definition
Certificates of type «Class B» issued by SG-PKI are combining the registered identity in a qualified identification process with a strong authentication. In the context of Federal Offices «Class B» are used for the strong authentication of natural persons on the system with user accounts.
Link
Translations
Definition
Unlike the standard class B certificates, functional Class B certificates are used for functional accounts like T-accounts and A-accounts.
Translations
Definition
“Control” (and its correlative meanings, “controlled by” and “under common control with”) means possession, directly or indirectly, of the power to: (1) direct the management, personnel, finances, or plans of such entity; (2) control the election of a majority of the directors ; or (3) vote that portion of voting shares required for “control” under the law of the entity’s Jurisdiction of Incorporation or Registration but in no case less than 10%.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Either a member of the United Nations OR a geographic region recognized as a Sovereign State by at least two UN member nations.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A not (yet) accredited issuing CA, which is publicly trusted by a certificate of an already accredited issuing CA, receives a so-called cross-certificate.
Translations
D
Definition
A natural person or Legal Entity that is not the CA but is authorized by the CA, and whose activities are not within the scope of the appropriate CA audits, to assist in the Certificate Management Process by performing or fulfilling one or more of the CA requirements found herein.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Link
Translations
Definition
In the context of “Class A” or “Class B”, a Digitally Signed Document refers to a PDF/A document with a valid signature executed with a certificate, issued by Swiss Government PKI.
Translations
Definition
A meta directory service (e.g. CIS, AIS or PEGASUS) used by the Swiss Government.
Translations
Definition
The name of an entry which is formed from the sequence of the relative distinguished names (RDNs) of the entry and each of its superior entries.
Source: https://www.itu.int/rec/T-REC-X.501/enAcronym
DN
Link
https://datatracker.ietf.org/doc/rfc4514/
Translations
Definition
The label assigned to a node in the Domain Name System.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31Translations
Definition
Sometimes referred to as the “owner” of a Domain Name, but more properly the person(s) or entity(ies) registered with a Domain Name Registrar as having the right to control how a Domain Name is used, such as the natural person or legal entity that is listed as the “Registrant” by WHOIS or the Domain Name Registrar.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A person or entity that registers Domain Names under the auspices of or by agreement with:
- the Internet Corporation for Assigned Names and Numbers (ICANN),
- a national Domain Name authority/registry, or
- a Network Information Center (including their affiliates, contractors, delegates, successors, or assignees).
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/
Translations
Definition
The set of all possible Domain Names that are subordinate to a single node in the Domain Name System.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
E
Definition
‘Electronic seal’ means data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the latter’s origin and integrity.
Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32014R0910Translations
Definition
Data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Link
Translations
Definition
Each enterprise active in Switzerland receives a unique enterprise identification number (UID). To ensure that numbers are correctly allocated and managed, the UID register is run by the Federal Statistical Office.
The UID register can be accessed via the following address: https://www.uid.admin.ch/Acronym
UID
Translations
Definition
An employee or agent of an organization unaffiliated with the CA who authorizes issuance of Certificates to that organization.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
The “Not After” date in a Certificate that defines the end of a Certificate’s validity period.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Extended key usage indicates one or more purposes for which the certified public key may be used, in addition to, or in place of the basic purposes indicated in the key usage.
Source: https://www.itu.int/rec/T-REC-X.509/enAcronym
EKU
Translations
Definition
An Extended Validation (EV) certificate is a type of TLS/SSL certificate that verifies that the certificate holder has undergone the most extensive level of vetting and identity background checks to certify that their website is authentic and legitimate. Extended validation means the certificate recipient and their website have completed a 16-point check to verify details such as: website domain, website owner, and the applicant’s legal, physical, and operational existence and identity.
Source: https://www.digicert.com/faq/public-trust-and-certificates/what-is-an-extended-validation-ev-ssl-certificateAcronym
EV
Translations
F
Definition
The FDF deals with a wide range of tasks, including the federal budget, both national and international finance, monetary and tax matters, customs and merchandise control and the implementation of legislation on alcohol. It also provides services for the whole of the Federal Administration, from IT to human resources, infrastructure and logistics.
Source: https://www.admin.ch/gov/en/start/departments/department-of-finance-fdf.htmlAcronym
FDF
Link
Translations
Definition
A standard for adoption and use by federal departments and agencies that has been developed within the Information Technology Laboratory and published by NIST, a part of the U.S. Department of Commerce. A FIPS covers some topic in information technology to achieve a common level of quality or some level of interoperability.
Source: https://csrc.nist.gov/glossaryAcronym
FIPS
Link
https://www.nist.gov/federal-information-processing-standards-fips
Translations
Definition
Federal law on certification services in the area of electronic signatures and other applications of digital certificates.
Acronym
SR 943.03 / ZertES
Link
SR 943.03 - Bundesgesetz vom 18. März 2016 über ... | Fedlex
Translations
Definition
The Federal Office for Customs and Border Security provides comprehensive security at the border – for the benefit of the public, the business community and the state.
Source: https://www.bazg.admin.ch/bazg/en/home/the-focbs/figures.htmlAcronym
FOCBS
Link
https://www.bazg.admin.ch/bazg/en/home.html
Translations
Definition
OFCOM steps in when the sponsoring codes contained in the Federal Radio and Television Act are infringed. It supervises radio and TV stations in Switzerland not just in terms of product placement, but also decides on frequency allocations and ensures that the Swiss Broadcasting Corporation fulfils its duty to provide programming for all parts of the country.
Source: https://www.uvek.admin.ch/uvek/en/home/detec/organisation/federal-offices.htmlAcronym
OFCOM
Link
Translations
Definition
The Federal Office of Information Technology, Systems and Telecommunication (FOITT) is one of the internal ICT service providers in the Federal Administration. It supports the administration by developing and providing efficient, secure, user and public-friendly IT solutions.
Source: https://www.bit.admin.ch/en/the-foitt-in-briefAcronym
FOITT
Link
Translations
Definition
For certificates of “Class A” there is a special option called “FreeDN”. This option provides the possibility to include in the certificate additional information according to the subscriber’s preference. Examples of such information are: Academic title, association with a particular office of the Swiss Government, a hierarchical position like Vice President etc.
Translations
Definition
A Domain Name that includes the Domain Labels of all superior nodes in the Internet Domain Name System.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Acronym
FQDN
Translations
G
Definition
A government-operated legal entity, agency, department, ministry, branch, or similar element of the government of a country, or political subdivision within such country (such as a state, province, city, county, etc.).
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
H
Definition
A hash value is a numerical value that is formed from a given data input by applying a so-called hash algorithm. Since a good algorithm produces different hash values for different data, it serves, among other things, as a «fingerprint» to ensure that documents are transmitted without being tampered with. If a document has been tampered with, the hash value calculated by the recipient will no longer match the hash value sent by the sender. The hash value encrypted with the sender's secret key is referred to as a digital signature.
Link
Translations
Definition
A Request that the CA flags for additional scrutiny by reference to internal criteria and databases maintained by the CA, which may include names at higher risk for phishing or other fraudulent usage, names contained in previously rejected certificate requests or revoked Certificates, names listed on the Miller Smiles phishing list or the Google Safe Browsing list, or names that the CA identifies using its own risk-mitigation criteria.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
I
Definition
The Swiss Government PKI is part of IDTR included in the business unit IAM.
Acronym
IDTR
Translations
Definition
A string of characters (not an IP address) in a Common Name or Subject Alternative Name field of a Certificate that cannot be verified as globally unique within the public DNS at the time of certificate issuance because it does not end with a Top Level Domain registered in IANA’s Root Zone Database.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
An internationalized domain name (IDN) is an Internet domain name that contains at least one label that is displayed in software applications, in whole or in part, in a language-specific script or alphabet, such as Arabic, Chinese, Cyrillic, Tamil, Hebrew or the Latin alphabet-based characters with diacritics or ligatures, such as French. These writing systems are encoded by computers in multi-byte Unicode. Internationalized domain names are stored in the Domain Name System as ASCII strings using Punycode transcription.
Acronym
IDN
Translations
Definition
The ITU-T X-series recommendations cover data networks, open system communications and security.
Acronym
ITU-T
Link
https://www.itu.int/rec/T-REC-X/en
Translations
Definition
In relation to a particular Certificate, the CA that issued the Certificate. This could be either a Root CA or a Subordinate CA.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
ITSO: Information Technology Security Officer
DSO: Department Security Officer
Source: https://www.ncsc.gov.uk/files/CCP-Guidance_to_certification_for_IA_professionals_2-3.pdfAcronym
ITSO / DSO
Link
Translations
J
K
Definition
The Private Key and its associated Public Key.
Translations
Definition
A user with special authorization to run the key recovery wizard. The KRA authorization is included in the functional scope of the LRA officer. The KRA authorization can also be granted to other employees upon special request.
Acronym
KRA
Translations
Definition
A Private Key is said to be compromised if its value has been disclosed to an unauthorized person, or an unauthorized person has had access to it.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A documented plan of procedures for the generation of a CA Key Pair.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
L
Definition
An association, corporation, partnership, proprietorship, trust, government entity or other entity with legal standing in a country’s legal system.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A Lightweight Certificate Policy (LCP) offering a quality of service less onerous than the NCP (requiring less demanding policy requirements) for use where a risk assessment does not justify the additional burden of meeting all requirements of the NCP (e.g. physical presence), for certificates used in support of any type of transaction (such as digital signatures, web authentication).
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
LCP
Translations
Definition
LDAP provides access to distributed directory services that act in accordance with X.500 data and service models. These protocol elements are based on those described in the X.500 Directory Access Protocol (DAP).
Source: https://datatracker.ietf.org/doc/rfc4511/Acronym
LDAP
Link
https://datatracker.ietf.org/doc/rfc4511/
Translations
Definition
An LRA is an organizational unit that is commissioned by the Swiss government PKI to carry out the identification of the applicant and to handle the processing of the certificates in the name of the Swiss government PKI. The LRA officer is responsible for the LRA's tasks, in addition to the hardware and software used for processing the certificates. This also includes, in particular, the premises where the applicants are identified, certificates are issued and customer files are stored.
Acronym
LRA
Translations
Definition
An LRA officer is as a person who performs the LRA functions (e.g. customer identification, creating or revoking a certificate) on behalf of the Swiss Government PKI.
Acronym
LRAO
Link
Swiss Government PKI - LRA-Officer
Translations
M
N
Definition
A Normalized Certificate Policy (NCP) which meets general recognized best practice for TSPs issuing certificates used in support of any type of transaction.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
NCP
Translations
Definition
An extended Normalized Certificate Policy (NCP+) which offers the same quality as that offered by the NCP for use where a secure cryptographic device (signing or decrypting) is considered necessary. The requirements for this CP include the policy requirements for the issuance and management of NCP certificates.
ource: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
NCP+
Translations
O
Definition
A unique alphanumeric or numeric identifier registered under the International Organization for Standardization’s applicable standard for a specific object or object class.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Acronym
OID
Link
CA Layout/Policies and Object Identifier (OID)
Translations
Definition
An online server operated under the authority of the CA and connected to its Repository for processing Certificate status requests. See also, Online Certificate Status Protocol.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
An online Certificate-checking protocol that enables relying-party application software to determine the status of an identified Certificate. See also OCSP Responder.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Acronym
OCSP
Link
https://www.bit.admin.ch/en/sg-pki-services-en#Online-Certificate-Status-Protocol-(OCSP)
Translations
Definition
An Organization is a legal entity represented by natural persons.
Acronym
O
Translations
Definition
“Organization Validated (OV) certificates are authenticated with nine validation checks and are considered a mid-level business certificate. With OV certificates, CAs authenticate domain ownership similar to DV certificates. But when you look beyond the lock of an OV certificate you will find more details about the company that owns the website. What distinguishes OV from DV is the steps taken by CAs to authenticate that the business organization (ie. Inc., Corp, LLC, Ltd, Pty Ltd, etc.) affiliated with the certificate is valid and remains in good standing.”
Source: https://www.digicert.com/difference-between-dv-ov-and-ev-ssl-certificatesAcronym
OV
Link
Translations
P
Definition
A company that controls a subsidiary company.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Permit F is a document for provisionally admitted foreigners. (This permit does not serve as evidence of the holder’s identity.)
Link
Permit F (provisionally admitted foreigners)
Translations
Definition
A personal identification number is a numeric or alphanumeric code that can be used to authenticate the user to the system.
Acronym
PIN
Translations
Definition
The PUK is used to reset a PIN in case of too many incorrect PIN entries or PIN loss. (In class B, the PUK is securely stored on the central systems of the SG-PKI and is never known to the certificate holders. During the PIN reset process, the PUK is automatically accessed.)
Acronym
PUK
Translations
Definition
Person who can execute the PIN reset wizard on their workstations for another person. All people participating in class B can be a PRU, provided that their workstations have two smart card readers.
Acronym
PRU
Translations
Definition
PKCS #10 defines a syntax for certification requests. A certification request consists of a distinguished name, a public key, and optionally a set of attributes, collectively signed by the entity requesting certification.
Acronym
PKCS #10
Link
https://datatracker.ietf.org/doc/rfc2986/
Translations
Definition
Personal Information Exchange Syntax PKCS #12 defines a transfer syntax for personal identity information, including private keys, certificates, miscellaneous secrets, and extensions. This standard supports direct transfer of personal information under several privacy and integrity modes.
Acronym
PKCS #12
Link
https://datatracker.ietf.org/doc/rfc7292/
Translations
Definition
Smartcards that go through the prestaging smartcard process of the SG-PKI before they are used. During prestaging, the smartcards are initialized, provided with 3 sets of 3 key pairs each, and secured with a PUK and a PIN.
Translations
Definition
The key of a Key Pair that is kept secret by the holder of the Key Pair, and that is used to create Digital Signatures and/or to decrypt electronic records or files that were encrypted with the corresponding Public Key.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
The key of a Key Pair that may be publicly disclosed by the holder of the corresponding Private Key and that is used by a Relying Party to verify Digital Signatures created with the holder’s corresponding Private Key and/or to encrypt messages so that they can be decrypted only with the holder’s corresponding Private Key.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
PKCS are a group of public-key cryptography standards devised and published by RSA Security LLC, starting in the early 1990s.
Acronym
PKCS
Link
Translations
Definition
A set of hardware, software, people, procedures, rules, policies, and obligations used to facilitate the trustworthy creation, issuance, management, and use of Certificates and keys based on Public Key Cryptography.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Acronym
PKI
Translations
Definition
The certificate is provided for third parties to enable the encryption of information.
Translations
Definition
A Certificate that is trusted by virtue of the fact that its corresponding Root Certificate is distributed as a trust anchor in widely-available application software.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Translations
Q
Definition
A qualified signature creation device (QSCD) is a specific hardware device that ensures that the signatory only has control of their private key. The device must meet the rigorous requirements laid out under Annex II of Regulation (EU) No 910/2014 (eIDAS).
Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32014R0910Acronym
QSCD
Translations
R
Definition
A Domain Name that has been registered with a Domain Name Registrar.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Employee of the administration with a department using regular certificates and authorized to register applicants, submit and - where appropriate - approve requests for regular certificates.
Translations
Definition
Any Legal Entity that is responsible for identification and authentication of subjects of Certificates, but is not a CA, and hence does not sign or issue Certificates. An RA may assist in the certificate application process or revocation process or both. When “RA” is used as an adjective to describe a role or function, it does not necessarily imply a separate body, but can be part of the CA.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Acronym
RA
Translations
Definition
RIO is as a person who performs identification tasks related to the issuing processes of a certificate on behalf of a LRA officer.
Acronym
RIO
Translations
Definition
An identification document or source of data used to verify Subject Identity Information that is generally recognized among commercial enterprises and governments as reliable, and which was created by a third party for a purpose other than the Applicant obtaining a Certificate.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A method of communication, such as a postal/courier delivery address, telephone number, or email address, that was verified using a source other than the Applicant Representative.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Natural or legal person that relies upon an electronic identification or a trust service.
NOTE: Relying parties include parties verifying a digital signature using a public key certificate.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/319401/Translations
Definition
An online database containing publicly-disclosed PKI governance documents (such as Certificate Policies and Certification Practice Statements) and Certificate status information, either in the form of a CRL or an OCSP response.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Standards issued by the Internet Engineering Task Force (IETF)
Acronym
RFC
Link
Translations
Definition
An IPv4 or IPv6 address that is contained in the address block of any entry in either of the following IANA registries:
- https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml
- https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
An algorithm used to support public key cryptography.
Acronym
RSA
Translations
Definition
An authentication certificate proving the certificate holder has been assigned the role identified by the certificate (on top of proving his identity).
Translations
Definition
The self-signed Certificate issued by the Root CA to identify itself and to facilitate verification of Certificates issued to its Subordinate CAs.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Link
Swiss Government PKI Root Certificates
Translations
Definition
The highest certification authority whose root certificate is distributed by the application software providers and which issues subordinate CA certificates. The respective issuing certification authorities (Issuing CA), which then issue the individual participant certificates, report to it.
Acronym
Root CA
Link
Swiss Government PKI Root Certificates
Translations
S
Definition
Security tokens are hardware components (e.g. HSM or smart cards or USB tokens) that are used to securely store digital keys and certificates. Access to the contents of the security token is usually protected by a PIN.
Translations
Definition
An algorithm used for hashing data to be digitally signed.
Acronym
SHA
Link
https://datatracker.ietf.org/doc/rfc6234/
Translations
Definition
Contractual agreement on the quality and quantity of services to be provided using clearly verifiable and comprehensible criteria (service level) accepted by both the user and the service provider, that define a set of service level objectives and related key performance indicators (KPI).
Source: https://www.electropedia.org/iev/iev.nsf/display?openform&ievref=871-01-06Acronym
SLA
Translations
Definition
Entity identified in a certificate as the holder of the private key associated with the public key given in the certificate.
NOTE: Relationship between subscriber and subject is described in document “EN 319 411-1” clauses 5.4.2 and 6.3.5.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Translations
Definition
Certification authority whose certificate is signed by the Root CA, or another Subordinate CA.
NOTE: A subordinate CA normally either issues end user certificates or other subordinate CA certificates.
Source: https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/Acronym
Sub-CA
Translations
Definition
A natural person or Legal Entity to whom a Certificate is issued and who is legally bound by a Subscriber Agreement or Terms of Use.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
An agreement between the CA and the Applicant/Subscriber that specifies the rights and responsibilities of the parties.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
A company that is controlled by a Parent Company.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
The Swiss Government PKI (formerly AdminPKI) is the official TSP of the federal administration. The services of the Swiss Government PKI (SG-PKI) are defined in the standard DTI service «Identity and Access Management». The SG-PKI products are used by administrative units, offices, cantons and municipalities.
Acronym
SG-PKI
Link
Translations
T
Definition
Provisions regarding the safekeeping and acceptable uses of a Certificate issued in accordance with these Requirements when the Applicant/Subscriber is an Affiliate of the CA or is the CA.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Acronym
ToU
Translations
Definition
Computer hardware, software, and procedures that are: reasonably secure from intrusion and misuse; provide a reasonable level of availability, reliability, and correct operation; are reasonably suited to performing their intended functions; and enforce the applicable security policy.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
U
V
Definition
A Certificate that passes the validation procedure specified in RFC 5280.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations
Definition
Someone who performs the information verification duties specified by these Requirements.
Source: https://cabforum.org/working-groups/server/baseline-requirements/requirements/Translations