SIST-TP ETSI/TR 102 040 V1.1.1:2005
(Main)International Harmonization of Policy Requirements for CAs issuing Certificates
General Information
- Abstract
To investigate the potential for international harmonization of policy requirements for CAs. This relates to the work in the US and other international activities specifying security management and policy requirements for CSPs issuing certificates (qualified or other) to ensure harmonization with the European standardization in this area. As well as influencing these other international activities, this work will identify variations in the requirements as specified in ETSI TS 101 456 (Policy requirements for CA issuing qualified certificates). This activity will include discussions and where possible achieve harmonisation with relevant organisations such as: ABA, FPKI, IETF, PKI Forum, WAP Forum.
- Status
- Published
- Publication Date
- 30-Apr-2005
- Technical Committee
- SPN - Services and Protocols for Networks
- Current Stage
- 6060 - National Implementation/Publication (Adopted Project)
- Start Date
- 01-May-2005
- Due Date
- 01-May-2005
- Completion Date
- 01-May-2005
Overview
SIST-TP ETSI/TR 102 040 V1.1.1:2005 addresses the international harmonization of policy requirements for Certification Authorities (CAs) issuing digital certificates. Published by SIST and based on an ETSI Technical Report, the standard investigates how various international frameworks and guidelines for certificate policy-such as in security management and trust services-can be aligned. The aim is to enable global interoperability of certificate policies, particularly ensuring European requirements (such as those from the European Electronic Signature Directive) are compatible and recognized internationally.
International harmonization is essential for the growth of secure digital services, especially in e-commerce, electronic signatures, and public key infrastructure (PKI). This standard facilitates mutual recognition of digital certificates, helps reduce technical and legal barriers, and supports international business and cross-border transactions.
Key Topics
- International Policy Alignment: Analysis and mapping of ETSI CA policy requirements with international frameworks such as those from ANSI, IETF, ISO, and ABA.
- Certificate Authority Requirements: Focus on both qualified and non-qualified certificates, outlining the importance of security management and policy consistency in digital trust services.
- Comparison of Standards: Identifies variations and similarities between ETSI TS 101 456 (for qualified certificates) and international standards such as IETF RFC 2527, ISO/IEC 14516, ANSI X9.79, and the ABA PKI Assessment Guidelines.
- Global Cooperation: Emphasizes collaboration with key organizations including the Internet Engineering Task Force (IETF), Public Key Infrastructure Forum (PKI Forum), American Bar Association (ABA), Asia-Pacific Economic Cooperation (APEC), and others.
- Recommendations for Future Alignment: Encourages targeting harmonization efforts on standards that most closely align with ETSI specifications, with a particular focus on financial services and electronic commerce sectors.
Applications
Harmonizing CA policy requirements has broad practical value for key digital sectors:
- E-commerce: Enables seamless trust and acceptance of digital certificates across borders, simplifying secure online transactions.
- Electronic Signatures: Ensures electronic signature schemes are recognized internationally, meeting both European legislation and requirements from other jurisdictions.
- Financial Services: Provides a consistent framework for digital certificates in banking and financial environments, reducing redundancy and supporting regulatory compliance.
- Legal Assurance: Supports legal interoperability for PKI-based services by aligning policy requirements, facilitating reliable electronic identification, and supporting digital trust globally.
- Interoperability: Promotes standardization of certificate policies and practices, enhancing the global acceptance and usability of digital certificates.
Organizations issuing or relying on digital certificates benefit from reduced compliance burdens and increased international recognition, while users gain confidence in the security and trustworthiness of electronic transactions.
Related Standards
Harmonization relies on established and emerging standards, including:
- ETSI TS 101 456: Policy requirements for certification authorities issuing qualified certificates.
- ETSI TS 102 042: Policy requirements for CAs issuing public key certificates.
- IETF RFC 2527: Internet X.509 Public Key Infrastructure Certificate Policy and Practices Framework.
- ISO/IEC 14516: Security techniques and guidelines for trusted third-party services.
- ANSI X9.79: PKI Policies and Practices Framework (adopted for financial services).
- ABA PKI Assessment Guidelines (PAG): Legal and policy framework for PKI.
- ISO 21188: Public Key Infrastructure for Financial Services - Practices and Policy Framework.
- Directive 1999/93/EC: European Electronic Signature Directive.
By fostering active collaboration among these standards and organizations, SIST-TP ETSI/TR 102 040 V1.1.1:2005 provides a pathway toward true international harmonization of CA policy requirements, supporting secure, cross-border digital trust services.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
SIST-TP ETSI/TR 102 040 V1.1.1:2005 is a technical report published by the Slovenian Institute for Standardization (SIST). Its full title is "International Harmonization of Policy Requirements for CAs issuing Certificates". This standard covers: To investigate the potential for international harmonization of policy requirements for CAs. This relates to the work in the US and other international activities specifying security management and policy requirements for CSPs issuing certificates (qualified or other) to ensure harmonization with the European standardization in this area. As well as influencing these other international activities, this work will identify variations in the requirements as specified in ETSI TS 101 456 (Policy requirements for CA issuing qualified certificates). This activity will include discussions and where possible achieve harmonisation with relevant organisations such as: ABA, FPKI, IETF, PKI Forum, WAP Forum.
To investigate the potential for international harmonization of policy requirements for CAs. This relates to the work in the US and other international activities specifying security management and policy requirements for CSPs issuing certificates (qualified or other) to ensure harmonization with the European standardization in this area. As well as influencing these other international activities, this work will identify variations in the requirements as specified in ETSI TS 101 456 (Policy requirements for CA issuing qualified certificates). This activity will include discussions and where possible achieve harmonisation with relevant organisations such as: ABA, FPKI, IETF, PKI Forum, WAP Forum.
SIST-TP ETSI/TR 102 040 V1.1.1:2005 is classified under the following ICS (International Classification for Standards) categories: 35.040.01 - Information coding in general. The ICS classification helps identify the subject area and facilitates finding related standards.
SIST-TP ETSI/TR 102 040 V1.1.1:2005 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-maj-2005
Mednarodna uskladitev politike zahtev za overitelje (certifikacijske
agencije/organe), ki izdajajo certifikate
International Harmonization of Policy Requirements for CAs issuing Certificates
Ta slovenski standard je istoveten z: TR 102 040 Version 1.1.1
ICS:
35.040 Nabori znakov in kodiranje Character sets and
informacij information coding
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
Technical Report
International Harmonization
of Policy Requirements for CAs issuing Certificates
2 ETSI TR 102 040 V1.1.1 (2002-03)
Reference
DTR/SEC-004015
Keywords
e-commerce, electronic signature, public key,
trust services, security
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, send your comment to:
editor@etsi.fr
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 2002.
All rights reserved.
ETSI
3 ETSI TR 102 040 V1.1.1 (2002-03)
Contents
Intellectual Property Rights.4
Foreword.4
1 Scope.5
2 References.5
3 Definitions and abbreviations.5
3.1 Definitions.5
3.2 Abbreviations.6
4 Objective.6
5 Relevant activities.6
5.1 Introduction.6
5.2 IETF PKIX policy and practices framework.6
5.3 ISO SC27 TTP guidelines .7
5.4 ABA PKI assessment guidelines .7
5.5 APEC TEL eSTG .7
5.6 ANSI X9.79 - PKI policy and practices framework.7
5.7 ISO TC68 - PKI policy and practices framework .8
6 Recommendations.8
History .9
ETSI
4 ETSI TR 102 040 V1.1.1 (2002-03)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web
server (http://webapp.etsi.org/IPR/home.asp).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web
server) which are, or may be, or may become, essential to the present document.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee Security (SEC).
ETSI
5 ETSI TR 102 040 V1.1.1 (2002-03)
1 Scope
The present document presents the results of ongoing work to harmonize existing ETSI technical specification on policy
requirements for certification authorities (TS 101 456 [1] and TS 102 042 [2]) with other internationally recognized
standards and related activities.
The aim of the present document is to identify the way forward to meet the requirements of European Electronic
Signature Directive 1999/93/EC [5] whilst operating within an internationally harmonized certificate policy framework
to facilitate cross recognition between PKI policy environments.
2 References
For the purposes of this Technical Report (TR) the following references apply:
[1] ETSI TS 101 456: "Policy requirements for certification authorities issuing qualified certificates".
[2] ETSI TS 102 042: "Policy requirements for certification authorities issuing public key
certificates".
[3] RFC 2527: "Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices
Framework".
[4] ISO/IEC 14516: "Information technology - Security techniques - Guidelines on the use and
management of Trusted Third Party services".
[5] Directive 1999/93/EC of the European Parliament and of the Council of 13 December 1999 on a
Community framework for electronic signatures.
[6] American Bar Association: "PKI Assessment Guidelines (PAG)".
[7] ANSI X9.79: "Public Key Infrastructure (PKI) Practices and Policy Framework".
[8] ISO/TC68/SC2 N1140 - New Work Item Proposal - Public Key Infrastructure for Financial
Services - Practices and Policy Framework.
NOTE: This work item has been agreed and the resulting standard has been designated the identifier ISO 21188.
3 Definitions and abbreviations
3.1 Definitions
For the purposes of the present document, the following terms and definitions apply:
certificate: public key of a user, together with some other information, rendered un-forgeable by encipherment with the
private key of the certification authority which issued it
certificate policy: named set of rules that indicates the applicability of a certificate to a particular community and/or
class of application with common security requirements
certification authority: authority trusted by one or more users to create and assign certificates
certification practice statement: statement of the practices which a certification authority employs in issuing
certificates
ETSI
6 ETSI TR 102 040 V1.1.1 (2002-03)
3.2 Abbreviations
For the purposes of the present document, the following abbreviations apply:
ABA American Bar Association
ANSI American National Standards Institute
APEC Asia-Pacific Economic Community
CA Certification Authority
EESSI European Electronic Signature Standardization Initiative
IETF Internet Engineering Task Force
ISO International Organization for Standardization
PAG PKI Assessment Guidelines (document published by the ABA [6])
PKI Public Key Infrastructure
4 Objective
The major objective of the present document on international certificate policy harmonization is that other
internationally recognized policies are harmonized with CA policy requirements which meet the requirements of
European electronic signature Directive [5] and other equivalents which are not constrained by the European legal
framework.
Thus, the main aim of harmonization is:
- To ensure that European CAs, both operating within the framework of European Directive and more generally,
have at least equal recognition in the wider international marketplace;
- To ensure that certification schemes accredited under the internationally recognized standards are recognized to
meet the security and management re
...



