Summary

  • RFC 3647 makes Certificate Policies and Certification Practice Statements easier to draft and compare, but it does not define a particular policy, prescribe a particular practice or attest that a declared control ran.
  • Leaders should join every material CP/CPS clause to a named owner, performed event, immutable evidence, independent observation, published status and relying-party outcome instead of treating a policy OID or audit label as proof.

The first useful distinction is grammatical. A Certificate Policy says what participants must do. A Certification Practice Statement says how a CA or organization says it implements those requirements. RFC 3647 is unusually explicit about that division. A CP generally spans applications, communities or multiple CAs. A CPS normally belongs to one CA or organization. One CPS can support several policies, and several CAs with different CPSs can support the same policy.

That relationship defeats a common automation shortcut. A policy object identifier in a certificate is not a fingerprint of one operating environment. It is the issuing CA’s declaration that a policy applies. Path processing can test whether acceptable policy identifiers appear through a chain and whether mappings or constraints permit them. It cannot reconstruct the people in the room, the device state, the authorization record or the witness signatures for a key-generation event.

The plain-text edition sets a narrower scope than the confidence often projected onto it. The RFC explains CP and CPS concepts and offers writers and users a framework. It does not define a specific CP or CPS, and it does not recommend which particular requirements or practices should appear. It calls the framework flexible rather than rigid. A conforming outline is a disclosure architecture, not a certification result.

The outline is powerful because it forces unlike institutions to discuss the same nine families: introduction; publication and repository duties; identification and authentication; certificate lifecycle; physical, management and operational controls; technical controls; certificate, CRL and OCSP profiles; compliance assessment; and business and legal matters. It even recommends preserving a heading when the answer is no stipulation. That makes an omission visible. It does not turn the omission into a control.

This is where a procurement scorecard can become deceptive. A parser sees all nine sections and awards completeness. Yet RFC 3647 permits a topic to contain no requirement or no disclosure. Sensitive procedures may also live outside the public CPS. The right machine result is therefore not “complete.” It is a map: declared, unstipulated, confidential, delegated, independently tested, or unsupported. Each status requires a different follow-up.

The legal layer is separate again. RFC 3647 says many CPs and CPSs are informational or disclosure documents. A CPS is not automatically a contract. A subscriber or relying-party agreement may incorporate it by reference, or it may not. A certificate’s policy qualifier may point to terms, but a pointer does not settle assent, governing law, liability or the scope of reliance. Legal incorporation and technical control performance need separate evidence.

Repository language illustrates the operational gap. A CPS can name the repository operator, publication frequency, access rules and the objects that should be available. To prove a particular relying-party experience, the organization still needs the object version, publication time, retrieval endpoint, observed bytes, freshness rule and application decision. “We publish hourly” is a target. A timestamped retrieval is an observation.

Revocation expands one apparent event into a clocked chain. RFC 3647 invites drafters to specify who may request revocation, how the requester is authenticated, the subscriber’s reporting window, the CA’s processing target, CRL frequency, publication latency, OCSP availability and the relying party’s checking duty. A dashboard that stores only revoked=true destroys the very delays that determine exposure.

RFC 6960 defines OCSP, while RFC 5019 profiles it for high-volume environments. Those protocols can provide a status observation with its own authorization and freshness semantics. They do not prove when the compromise was discovered, who approved the request, whether every publication surface converged or whether an application rejected the certificate. The closeout record has to join those events.

Key management needs the same discipline. RFC 3647’s checklist asks who generated a key pair, whether hardware or software did it, how a private key was delivered, whether proof of possession occurred, how many people controlled sensitive actions, how backups and archives were protected, and how keys were activated, deactivated and destroyed. The sentence “dual control is required” is not two operator identities, two independent authorizations and a device transcript. A backup policy is not an inventory proving which state was copied or later restored.

Compromise recovery is more than publication of a plan. The framework asks how a secure environment is re-established, which certificates and entity keys are revoked, how a new public key reaches users, how subjects are re-certified and how continuity is maintained. Each transition needs a receipt. Otherwise the plan can be correct while old trust remains live in a repository, cache or application.

Assessment also has boundaries. RFC 3647 separates audit scope or methodology, frequency or triggering event, assessor qualifications, assessor independence, covered topics, deficiency response and communication of results. “Audited annually” does not identify the sampled population, period, exclusions or open findings. It says even less about an event after the audit window. A defensible badge must resolve to the exact report, scope, evidence period and remediation state.

The underlying certificate machinery remains distinct. RFC 5280, as updated in part by RFC 6818, defines Internet X.509 certificate and CRL profiles and path validation. A path can satisfy those rules without proving the history of every procedure declared in a CPS. Syntax, signature, name constraints, policy processing, status and operational provenance answer different questions.

The RPKI documents provide a useful concrete comparison without turning this Article into an RPKI deployment claim. RFC 6484 is a Certificate Policy. RFC 7382 is an RFC 3647-based template for a Certification Practice Statement. The pair shows why policy and implementation disclosure are different artifacts.

Other RPKI specifications add machine-observable layers. RFC 6487 profiles certificates and CRLs. RFC 6481 defines repository publication points. RFC 6486 gives relying parties a signed manifest with which to detect specified missing or stale objects. Those are stronger receipts than a prose promise, but even a manifest does not attest to every physical, personnel or recovery control in a CPS.

The lineage matters. RFC 3647 replaced RFC 2527 with an incremental framework shaped by deployment and legal review. Its current record can be checked through the Datatracker page, RFC Editor information page, history and errata search. At this evidence freeze, the errata are editorial: five verified items and one held for document update. None turns the framework into a live conformance service.

Even identifiers have a limited job. The IANA SMI Numbers registry supports shared object-identifier vocabulary. Registration helps systems name the same thing. It does not prove that an operator followed a policy, that an assessor examined a control or that a relying party accepted the result.

Heng Lu’s accounts of running-code primacy, minimum initial specification and reality layers supply the governing test. A common outline is useful when it makes claims portable and comparable. It becomes a source of symbolic power when publication is allowed to stand in for implementation, observation and reliance.

The operating record should therefore keep each layer intact: policy identifier and version; applicable CP; CPS clause; named owner and delegated participant; ceremony or action ID; operator, witness and device evidence; audit scope and time; certificate and status publication; relying-party retrieval; path and policy result; application decision. A missing arrow is uncertainty. It is not permission to promote the preceding document into proof.