[cabfpub] Private key control

Jeremy Rowley jeremy.rowley at digicert.com
Thu Oct 23 01:56:55 UTC 2014

During the Code Signing BR discussion a few weeks ago, we noticed that the Baseline Requirements lack a definitive requirement for the CA to confirm that the Application is properly associated with the Public Key being included in the certificate.  We'd like to remedy this oversight.  What does everyone thing about adding a section similar to the following to the BRs?

Section 11.1.5    Verification of Key Pair Association
Prior to issuing a Certificate, the CA MUST verify that the Applicant's Private Key is properly associated with the Public Key and a subject name to be included in the Certificate. The CA MAY verify this association by obtaining a CSR from the Applicant.

