Talk With an Expert

Decommissioning Certification Authorities

Decommissioning Certification Authorities (PDF, 1.89MB)Published: 10 Mar, 2002
Created by:
Claudia Lukas

Certification Authorities (CA) based on Public Key Infrastructure (PKI) are in regular use throughout the world. While there are increasing numbers of CA's initiated each month, the time may have come to decommission a 'pioneer' CA installed in the early years of commercial PKI roughly 1995 - 1999. Business financial legal or simply technology shelf life may lead to terminating a CA. Terminating a CA is as important an event as its initiation - both require planning physical logical and human aspects. Security of information and reputation is at risk. The current and future needs of subscribers and other relying parties require consideration. In contrast to the many sources available to learn about setting up a CA there is a shortage of published reports and best practices on decommissioning a Certification Authority. Standards organizations provide a few guidelines for defining CA termination in the CA's Certificate Policy (CP) and Certification Practice Statement (CPS). This paper reviews these guidelines and discusses terminating a Certification Authority.