ORC ECA Header Image
   Domain Controller Certificate Procedures

 
 

Status Bar - Online Application

In order to request, renew, and use a Domain Controller Certificate issued under the ORC ECA CPS, you, the applicant company, and Domain Controller Certificate Subscriber must agree to the following obligations.

Server Certificate Logo
Bullet To accurately represent themselves in all communications with ORC and the PKI, and abide by all the terms, conditions, and restrictions levied upon the use of the issued private key(s) and certificate(s).
Bullet To protect the certificate private key from unauthorized access in accordance with the Private Key Protection section of the ECA CPS.
Bullet To immediately report to the RA and request certificate revocation processing if Private Key Compromise is suspected.
Bullet In the event of a PKI Sponsor change, due to the verified individual having left the employ of the applicant company or is no longer assigned as the PKI Sponsor for the certificate(s), the applicant company must designate a new PKI Sponsor for the certificate(s). The applicant company must designate a new PKI Sponsor and the new PKI Sponsor must complete a new identity verification.
Bullet When renewing the domain controller certificate the PKI Sponsor must complete a new identity verification.
Bullet Confirm that you (the PKI Sponsor) are a current employee of the applicant company and that you are authorized by the applicant company to obtain component/server certificates for the company by completing and submitting the Component/Server Authorization letter.
Bullet That the domain controller designated in the certificate request is the only system on which the certificate is to be installed.
Bullet To use the certificate only for authorized applications which have met the requirements of this CPS.
Bullet To use the certificate only for the purpose for which it was issued, as indicated in the key usage extension.
Bullet To report any changes to information contained in the certificate to the appropriate RA for certificate reissue processing.
   

A Domain Controller Certificate Subscriber and their applicant organization found to have acted in a manner inconsistent with these obligations is subject to revocation of LRA responsibilities and/or revocation of all Domain Controller Certificates issued to that applicant organization.



I understand that during this process I will be generating my key pair and will possess the only copy of my private key on the workstation/computer (or hardware token) from which I am making my request. If lost, damaged, or compromised, I will be responsible for requesting and incurring the costs of a new certificate.


Return to Last Page   I Agree button