Incorrect standard for Certification Authorities in Mauritius

6 February 2015 by S. Moonesamy

Standards for Certification Authorities

Under section 18 (z) of the Information and Communication Technologies Act 2001, the ICT Authority is the Controller of Certification Authorities in Mauritius. The Controller of Certification Authorities (CCA) published the CCA Directive 1 of 2010. The document states that:

1. The standards followed by the Certification Authority for carrying
out its functions:

(1) Every Certification Authority shall observe the following standards
for carrying out different activities associated with its functions.

(a) PKIX (Public Key Infrastructure) Public Key Infrastructure as
recommended by Internet Engineering Task Force (IETF) document
draft-ietf-pkix-roadmap-09 for “Internet X.509 Public Key
Infrastructure” (July , 2002);

draft-ietf-pkix-roadmap-09 for “Internet X.509 Public Key Infrastructure”

According to draft-ietf-pkix-roadmap-09 "it is inappropriate to use Internet-Drafts as reference material or to cite them other than as work in progress." Section 1 of the Internet-Draft states that:

This document is an informational Internet-Draft that provides a
"roadmap" to the documents produced by the PKIX working group. It is
intended to provide information; there are no requirements or
specifications in this document.

Conclusion

The usage of an Internet-Draft as a standard is incorrect. Given that the Internet-Draft does not contain any requirement or specification it is not possible to use it as a standard.

1. Information and Communication Technologies Act 2001
2. Controller of Certification Authorities - The CCA Directive 1 of 2010
3. Internet X.509 Public Key Infrastructure: Roadmap - draft-ietf-pkix-roadmap-09.txt