How should a QTSP choose between QCP-n, QCP-l, QSCD, and website profiles?
Use five inputs: intended use, subject type, condition, website assurance route, and issuing service scope. EN 319 411-2 defines separate policy identifiers for qualified certificates issued to natural persons, qualified certificates issued to legal persons, qualified certificates tied to a QSCD, and a . If the intended use is outside signature, seal, or website authentication, these seven profiles do not answer the certificate-policy question.
For signatures, the natural-person route is QCP-n, and QCP-n- is used where the private key related to the certified public key resides in a QSCD. For seals, the legal-person route is QCP-l, and QCP-l-qscd is used where the private key resides in a QSCD. For website authentication, EN 319 411-2 separates QEVCP-w, QNCP-w, and QNCP-w-gen depending on the certificate route and the assurance model behind it. QEVCP-w follows EVCG-based requirements, QNCP-w follows BRG-based requirements for natural or legal persons, and QNCP-w-gen is the general-purpose website-authentication route.
Use the subject and assurance model together. A natural-person signature route points to QCP-n or QCP-n-, and a legal-person seal route points to QCP-l or QCP-l-qscd. For website authentication, QEVCP-w applies only to the EVCP and EVCG route for a legal person; QNCP-w applies to a natural or legal person under NCP plus IVCP or OVCP and the Baseline Requirements; QNCP-w-gen is the general-purpose NCP and WEB-tagged route. Do not choose QEVCP-w merely because the subscriber is a legal person.
- Use QCP-n when the qualified certificate is issued to a natural person for advanced electronic signatures based on a qualified certificate.
- Use QCP-l when the qualified certificate is issued to a legal person for advanced electronic seals based on a qualified certificate.
- Use QCP-n- or QCP-l-qscd only when the selected signature or seal route requires the private key to reside in a QSCD.
- Use QEVCP-w for the EVCP and EVCG route, QNCP-w for the NCP plus IVCP or OVCP and BRG route, and QNCP-w-gen for the NCP plus WEB-tagged general-purpose route.
- Record the rejected profiles and why they do not fit. For example, a legal-person website subscriber does not by itself select QEVCP-w; the service also needs the EVCP and EVCG assurance route.
Defines the seven EU qualified certificate policy identifiers and describes their natural-person, legal-person, QSCD, and website-authentication use cases.
Provides the general certificate policy, CPS, subscriber, repository, and lifecycle requirements that EN 319 411-2 builds on.
Legal context for qualified trust services, qualified certificates, electronic signatures, electronic seals, and website authentication.