Sign in
P-3ProposedGlobal, Registry Council

Certificates

Version
v1
In force since
Not yet
Next review
At adoption
Snapshot
None yet
Adopted by
Proposed for founding adoption
Signature
At adoption
Log entry
Not appended yet
Binding text
English

Proposed, not in force

Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.

1

Scope

1.1
Bindingp3-c1

This policy binds the GOpenCDR certificate authority, which issues TLS server certificates for names in GOpenCDR TLDs and for nothing else. It is not part of the public web PKI, and a person trusts it only by installing its root after a confirmation that says what that means.

2

Name constraints

2.1
Enforced rulep3-c2Not enforced yet

Every CA certificate carries a critical name constraints extension that permits only the current GOpenCDR TLDs as DNS names and excludes every IPv4 and IPv6 range.

Rule ca.name_constraints. Limits: No scope may widen the permitted set beyond the TLDs in the root.

2.2
Bindingp3-c3

The root is re-issued with the same key whenever the set of TLDs changes, and each re-issued root is published through the channels P-2 8.1 names.

2.3
Bindingp3-c4

A TLD in sunset leaves the name constraints before its IANA delegation, so that no certificate for a name in it validates against a current root.

3

Issuance

3.1
Enforced rulep3-c5Not enforced yet

Certificates are issued only through ACME, RFC 8555, after challenges whose every DNS lookup validates with DNSSEC against the GOpenCDR anchors. A wildcard name needs a DNS challenge.

Rule ca.validation.

3.2
Enforced rulep3-c6Not enforced yet

CAA is checked for every name through validated lookups, and a record that does not permit the GOpenCDR CA stops the issuance.

Rule ca.caa.

3.3
Enforced settingp3-c7Not enforced yet

A certificate is valid for at most 45 daysfixed.

3.4
Enforced rulep3-c8Not enforced yet

Every certificate is logged in the GOpenCDR certificate transparency log before it is used.

Rule ca.ct.

4

Revocation

4.1
Enforced settingp3-c9Not enforced yet

Status is published only through revocation lists, renewed at least every 24 hoursfixed and within 1 hourfixed of a revocation. There is no OCSP.

4.2
Enforced settingp3-c10Not enforced yet

A certificate is revoked within 24 hoursfixed of establishing that its key is compromised, that its subscriber no longer controls a name in it, that a name in it was withdrawn or its TLD left GOpenCDR, that it was issued wrongly, that the subscriber agreement was broken, or that a court or an authority orders it.