-
Notifications
You must be signed in to change notification settings - Fork 111
Open
Open
Copy link
Labels
questionFurther information is requestedFurther information is requested
Description
Description of Issue:
A user needs to build a certificate bundle for trust store management. How do they identify what paths they need?
There are multiple pages in FPKI guide that show a separate process to figure out a path, but nothing on how to build a bundle.
- PIV CAs and Agencies - This page shows which agencies use which issuer and specifically which issuer certificate. Someone would need to manually connect the issuer's name back to either FCPCA G2 or a certificate under FCPCAG2.
- FPKI Graph - This page shows a generic path using the subject name. A user could take the issuer subject name and find a complete path. The graph doesn't share the specific certificate they need, just a generic path.
- FCPCA G2 - This page shows which specific certificates are issued under the Federal Common Policy.
Once they know what certificates they need, they need to figure out how to make a bundle. This is only for PIV. With agencies issuing PIV-I, there is no guidance on how to identify or build a path for PIV-I.
One practical example is if an agency is presented as a PIV or PIV-I their existing configuration builds a path. How can an agency verify that path is correct?
Suggestions
Create a new page on how to identify a path and then build a bundle for both PIV or PIV-I
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requested