4

What is a practice for issuing TSA (Time Stamping Authority) certificates?

I read that TSA certificates should be issued directly from Root CA, but basically TSA certificate is end entity certificate and Root CA should't be issuing certificates for end entities.

Should I issue TSA certificate from Root CA or should I issue dedicated Intermediate CA for issuing TSA certificate?

gowenfawr
  • 71,975
  • 17
  • 161
  • 198
user1563721
  • 1,099
  • 11
  • 22

1 Answers1

1

Your argument is correct, in most cases you should create an intermediate certificate, which issues your timestamping certificate.

The only reason I can think of for creating it directly from root would be, that managers of very small PKIs want to avoid the additional administrative overhead of an extra intermediate CA for a certificate type which will only be issued very seldom (probably less than one certificate per year). It can be done in a private enterprise setting, but it is definitely bad practice.

mat
  • 1,243
  • 7
  • 14