9. References

10. Notes

   3.  The term "meaningful" means that the name form has commonly
       understood semantics to determine the identity of a person and/or
       organization.  Directory names and RFC 822 names may be more or
       less meaningful.

   4.  The subject may not need to prove to the CA that the subject has
       possession of the private key corresponding to the public key
       being registered if the CA generates the subject's key pair on
       the subject's behalf.

   5.  Examples of means to identify and authenticate individuals
       include biometric means (such as thumb print, ten finger print,
       and scan of the face, palm, or retina), a driver's license, a
       credit card, a company badge, and a government badge.

   6.  Certificate "modification" does not refer to making a change to
       an existing certificate, since this would prevent the
       verification of any digital signatures on the certificate and
       cause the certificate to be invalid.  Rather, the concept of
       "modification" refers to a situation where the information
       referred to in the certificate has changed or should be changed,
       and the CA issues a new certificate containing the modified
       information.  One example is a subscriber that changes his or her
       name, which would necessitate the issuance of a new certificate
       containing the new name.

   7.  The n out of m rule allows a private key to be split in m parts.
       The m parts may be given to m different individuals.  Any n parts
       out of the m parts may be used to fully reconstitute the private
       key, but having any n-1 parts provides one with no information
       about the private key.

   8.  A private key may be escrowed, backed up, or archived.  Each of
       these functions has a different purpose.  Thus, a private key may
       go through any subset of these functions depending on the
       requirements.  The purpose of escrow is to allow a third party
       (such as an organization or government) to obtain the private key
       without the cooperation of the subscriber.  The purpose of back
       up is to allow the subscriber to reconstitute the key in case of
       the destruction or corruption of the key for business continuity
       purposes.  The purpose of archives is to provide for reuse of the
       private key in the future, e.g., use to decrypt a document.

   9.  WebTrust refers to the "WebTrust Program for Certification
       Authorities," from the American Institute of Certified Public
       Accountants, Inc., and the Canadian Institute of Chartered
   11. All or some of the following items may be different for the
       various types of entities, i.e., CA, RA, and end entities.

11. List of Acronyms

ABA - American Bar Association CA - Certification Authority CP - Certificate Policy CPS - Certification Practice Statement CRL - Certificate Revocation List DAM - Draft Amendment FIPS - Federal Information Processing Standard I&A - Identification and Authentication IEC - International Electrotechnical Commission IETF - Internet Engineering Task Force IP - Internet Protocol ISO - International Organization for Standardization ITU - International Telecommunications Union NIST - National Institute of Standards and Technology OID - Object Identifier PIN - Personal Identification Number PKI - Public Key Infrastructure PKIX - Public Key Infrastructure (X.509) (IETF Working Group) RA - Registration Authority RFC - Request For Comment URL - Uniform Resource Locator US - United States
   Stephen S. Wu
   Infoliance, Inc.
   800 West El Camino Real
   Suite 180
   Mountain View, CA  94040

   Phone:  (650) 917-8045
   Fax:    (650) 618-1454
