go to NIST home page go to CSRC home page go to Focus Areas page go to Publications page go to Advisories page go to Events page go to Site Map page go to ITL home page CSRC home page link
header image with links

CSOR home page
 
Comments
 
Cryptographic Algorithm
Registration

CSOR Documents
 
CSOR Information
 
Disclaimer
 
IOSP Registration

 
PKI Registration
 
Security Label
Registration

 
PKI Homepage


CSRC Homepage

CSRC Site Map

CSRC Search Engine:


Computer Security Objects Register header image

CSOR Public Key Infrastructure (PKI) Objects Registration

The CSOR has allocated the following registration branch for Public Key Infrastructure (PKI) objects:

csor-pki={joint-iso-ccitt(2) country(16) us(840) organization(1) gov(101) csor(3) pki(2)}.

Object-specific registration procedures for PKI-related objects will be specified in the document General Procedures for Registering Computer Security Objects (NISTIR 5308).  The procedures will indicate the information that must be provided when registering objects under this branch.  A registration branch for Certificate Policies, csor-certpolicy={csor-pki cert-policy(1)} is currently available.  Other types of PKI objects will be registered as needed. 

Additional information on Federal PKI activities is available from the NIST PKI Page.

Registered Objects

ACES Registered Objects

There are five objects registered to support the  ACES project.  These objects define an arc for policies associated with the GSA ACES project, and four distinct policies. Note that the four policies are all defined within a single document.

-- the ACES policy arc
aces OBJECT IDENTIFIER ::= { csor-certpolicy 1 }

-- the aces policy OIDs

--
aces-ca OBJECT IDENTIFIER ::= { aces 1 }
aces-identity OBJECT IDENTIFIER ::= { aces 2 }
aces-business-rep OBJECT IDENTIFIER ::= { aces 3 }
aces-relying-party OBJECT IDENTIFIER ::= { aces 4 }

U.S. Patent and Trademark Office Registered Objects

The following arc has been reserved for PKI policies under development at U.S. Patent and Trademark Office.

pto-policies OBJECT IDENTIFIER ::= { csor-certpolicy 2 }

Federal Bridge Certification Authority Registered Objects

Six objects have been registered to support the Federal Bridge Certification Authority. The first object is an arc for FBCA policies; the remaining five objects identify the five certificate policies used by the Federal Bridge Certification Authority. The five polices are defined by the FBCA certificate policy.

fbca-policies OBJECT IDENTIFIER ::= { csor-certpolicy 3 }

id-fpki-certpcy-rudimentaryAssurance OBJECT IDENTIFIER ::= { fbca-policies 1 }
id-fpki-certpcy-basicAssurance OBJECT IDENTIFIER ::= { fbca-policies 2 }
id-fpki-certpcy-mediumAssurance OBJECT IDENTIFIER ::= { fbca-policies 3 }
id-fpki-certpcy-highAssurance OBJECT IDENTIFIER ::= { fbca-policies 4 }
id-fpki-certpcy-testAssurance OBJECT IDENTIFIER ::= { fbca-policies 5 }

National Institute of Standards and Technology Registered Objects

The following arc has been reserved for PKI policies under development at National Institute of Standards and Technology.

nist-policies OBJECT IDENTIFIER ::= { csor-certpolicy 4 }

U.S. Treasury Department's Financial Management Service (FMS) Registered Objects

Two objects have been registered to support the U.S. Treasury Department's  Financial Management Service (FMS) PKI.  The first object defines an arc for U.S. treasury PKI policies.  The second object is the FMS PKI policy.  The FMS policy is defined in this document.

treasury-policies  OBJECT IDENTIFIER ::= { csor-certpolicy 5 }
treasury-cp1  OBJECT IDENTIFER  ::= { treasury-policies 1 }

State Department Registered Objects

Five objects have been registered to support the U.S. State Department PKI. The first object is an arc for State Department policies; the remaining four objects identify the four certificate policies that may used by the State Department PKI. The four policies are defined by the State Department certificate policy.

state-policies OBJECT IDENTIFIER ::= { csor-certpolicy 6 }

state-basic OBJECT IDENTIFIER ::= { state-policies 1 }
state-low OBJECT IDENTIFIER ::= { state-policies 2 }
state-moderate OBJECT IDENTIFIER ::= { state-policies 3 }
state-high OBJECT IDENTIFIER ::= { state-policies 4 }

Federal Deposit Insurance Corporation Registered Objects

Five objects have been registered to support the Federal Deposit Insurance Corporation PKI. The first object is an arc for FDIC policiesi; the remaining four objects identify the four certificate policies that may used by the Federal Deposit Insurance Corporation PKI. The four policies are defined by the FDIC certificate policy.

fdic-policies OBJECT IDENTIFIER ::= { csor-certpolicy 7 }

fdic-basic OBJECT IDENTIFIER ::= { fdic-policies 1 }
fdic-low OBJECT IDENTIFIER ::= { fdic-policies 2 }
fdic-moderate OBJECT IDENTIFIER ::= { fdic-policies 3 }
fdic-high OBJECT IDENTIFIER ::= { fdic-policies 4 }

PKI Pilots and Testing Registered Objects

There are eleven objects registered to support PKI pilots and testing.  These objects define an arc for policies associated and ten distinct policies. These policies should never be inserted in "real" certificates, and no relying party should ever accept such a certificate to implement security services in a "real" application!  Note that the ten policies are all equivalent and are defined within a single test policy document.

-- test policy arc

csor-test-policies OBJECT IDENTIFIER  ::= { 2 16 840 1 101 3 2 1 48 }

-- test policy OIDs

test1 OBJECT IDENTIFIER ::= { csor-test-policies 1 } 
test2 OBJECT IDENTIFIER  ::= { csor-test-policies 2 } 
test3 OBJECT IDENTIFIER  ::= { csor-test-policies 3 } 
test4 OBJECT IDENTIFIER  ::= { csor-test-policies 4 } 
test5 OBJECT IDENTIFIER  ::= { csor-test-policies 5 } 
test6 OBJECT IDENTIFIER  ::= { csor-test-policies 6 } 
test7 OBJECT IDENTIFIER  ::= { csor-test-policies 7 } 
test8 OBJECT IDENTIFIER  ::= { csor-test-policies 8 } 
test9  OBJECT IDENTIFIER ::= { csor-test-policies 9 } 
test10 OBJECT IDENTIFIER  ::= { csor-test-policies 10 }


 

Last updated: July 29, 2005
Page created: April 14, 2000