How should a QTSP choose between QCP-n, QCP-l, QSCD, and website profiles?
Start with the relying-party purpose and subject type. EN 319 411-2 defines separate policy identifiers for qualified certificates issued to natural persons, qualified certificates issued to legal persons, qualified certificates tied to a QSCD, and qualified website authentication certificates.
For signatures, the natural-person route is QCP-n, and QCP-n-qscd is used where the private key related to the certified public key resides in a QSCD. For seals, the legal-person route is QCP-l, and QCP-l-qscd is used where the private key resides in a QSCD. For website authentication, EN 319 411-2 separates QEVCP-w, QNCP-w, and QNCP-w-gen depending on the certificate route and the assurance model behind it. QEVCP-w follows EVCG-based requirements, QNCP-w follows BRG-based requirements for natural or legal persons, and QNCP-w-gen is the general-purpose website-authentication route.
If the choice is still unclear, use the subject and assurance model as the tie-breaker: natural person plus signature points to QCP-n or QCP-n-qscd, legal person plus seal points to QCP-l or QCP-l-qscd, legal-person website authentication usually points to QEVCP-w, and natural or legal person website authentication under BRG points to QNCP-w. Use QNCP-w-gen when the website certificate needs the general-purpose route defined in EN 319 411-2 rather than the BRG or EVCG-specific route.
- Use QCP-n when the qualified certificate is issued to a natural person for advanced electronic signatures based on a qualified certificate.
- Use QCP-l when the qualified certificate is issued to a legal person for advanced electronic seals based on a qualified certificate.
- Use QCP-n-qscd or QCP-l-qscd only when the selected signature or seal route requires the private key to reside in a QSCD.
- Use QEVCP-w for a qualified website certificate based on EVCG, QNCP-w for a website certificate based on BRG, and QNCP-w-gen for the general-purpose website-authentication profile.
Defines the seven EU qualified certificate policy identifiers and describes their natural-person, legal-person, QSCD, and website-authentication use cases.
Provides the general certificate policy, CPS, subscriber, repository, and lifecycle requirements that EN 319 411-2 builds on.
Legal context for qualified trust services, qualified certificates, electronic signatures, electronic seals, and website authentication.