Category III: Foreign, Allied, or Coalition Partner PKIs or other PKIs
The Netherlands Ministerie van Defensie PKIoverheid Organisatie Persoon CA – G3 is cross-certified with the Federal Bridge via the CertiPath Bridge. However, Netherlands MOD does not currently publish their cross-certificate in a location discoverable during dynamic path building (a.k.a. “AIA chasing”). To utilize the cross-certificate path through the Federal Bridge, a system would need have the CertiPath Bridge CA – G3 > Ministerie van Defensie PKIoverheid Organisatie Persoon CA – G3 cross-certificate locally installed; this certificate can be found in the CertiPath Bridge SIA bundle at http://aia.certipath.com/IssuedBy-CertiPathBridgeCA-G3.p7c. When using this approach, a system should not install the Staat der Nederlanden Root CA – G3.
See the DoD PKI External Interoperability FAQ for more information on DoD approved partner PKI credentials.
Netherlands Ministry of Defence PKI
Current Certification Authorities (CAs) Details | See Section 44.2 of DoD Approved External PKIs Master Document |
Current CA Certificates | See Netherlands_Ministry_of_Defence folder in DoD Approved External PKI Certificate Trust Chains zip |
Approved Certificate Assurance Levels* | See Section 5.18 of DoD Approved External PKIs Master Document |
Certificate Revocation List (CRL) Distribution Points** | See Netherlands Ministry of Defence section of DoD Approved External CRL Distribution Points (CRLDPs) |
Online Certificate Status Protocol (OCSP) Responder URL(s)** | None |
Performs CA Rekeys? | No |
*As represented by OIDs listed in the Certificate Policies extension of the partner certificate; a certificate must assert at least one approved assurance level to be acceptable for use.
**Note: These lists are developed and maintained by DoD PKE based on CRLDP and AIA OCSP values asserted in sample certificates provided to DoD by the partner PKI for testing; they are provided for ease of reference and may not be exhaustive in all cases. Any CRL URL asserted in a CRLDP extension or OCSP URL asserted in an AIA extension of an approved certificate is approved for use by DoD relying parties.