80
Jumpstarting eMobility

Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

  • Upload
    others

  • View
    14

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Jumpstarting eMobility

Page 3: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 4: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 5: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 6: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 7: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 8: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 9: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 10: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 11: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 12: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 13: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 15: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 16: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 17: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 18: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

2

Page 19: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 20: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 21: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 22: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

o

Page 23: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

o

o

o

o

o

Page 24: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 26: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 27: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

. The

Page 28: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 29: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 30: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 31: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 32: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 33: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 34: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 35: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 36: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 37: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 38: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 39: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 40: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 41: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 42: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 43: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 44: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 45: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 46: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 47: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 48: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 49: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 50: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 51: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 52: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 53: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 54: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 55: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 56: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 57: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 58: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

o

o

o

o

o

o

o

o

Page 59: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

o

o

o

o

o

o

o

o

o

o

o

o

Page 60: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 61: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 62: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 63: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 64: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

ISO 15118-2 Certificate

Profiles

Cluster: V2G Root

Name: V2G Root Typ: Root

tbsCertificate Version 2 (X.509v3) SerialNumber Integer Signature ecdsa-with-SHA256

Issuer Country (x) Organization x Organization Unit (x) Common Name x Domain Component "V2G"

Validity 40 years Subject Country (x)

Organization x Organization Unit (x) Common Name x Domain Component "V2G"

SubjectPublic KeyInfo

Public Key x Cryptographic Algorithm id-ecPublicKey Parameters ECParameters (namedCurve secp256r1)

Extensions AuthorityKeyIdentifier (x) SubjectKeyIdentifier (x) / nc KeyUsage c

digitalSignature 0/1 nonRepudiation (contentCommitment) 0/1

keyEncipherment 0/1 dataEncipherment 0 keyAgreement 0/1 keyCertSign 1 cRLSign 1 encipherOnly 0 decipherOnly 0

ExtendedKeyUsage - CertificatePolicies (x) / nc BasicConstraints c

CA true PathLength -

CRLDistributionPoints (x) / nc Authority Information Access (OCSP)

(x) / nc id-ad-ocsp / location of the OCSP responder

Cryptographic Algorithm ecdsa-with-SHA256 Signature

Value Octect-String

Page 65: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

ISO 15118-2 Certificate

Profiles

Cluster: Charge Point Operator (CPO) OCSP

Name: CPO Sub-CA 1 CPO Sub-CA 2 SECC Leaf Cert OCSP Cert Type: Sub Sub Leaf Leaf

tbsCertificate Version 2 (X.509v3) 2 (X.509v3) 2 (X.509v3) 2 (X.509v3) SerialNumber Integer Integer Integer Integer

Signature ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Issuer Country (x) (x) (x) (x) Organization x x x x Organization Unit (x) (x) (x) (x) CommonName x x x x Domain Component "V2G" (x) "CPO" (x)

Validity 40 years 1-2 years 2-3 month up to 1 year Subject Country (x) (x) x -

Organization x x x x Organization Unit (x) (x) (x) (x) Common Name x x SECCID x Domain Component (x) (x) (x) (x)

SubjectPublic KeyInfo

Public Key x x x x Cryptographic Algorithm id-ecPublicKey id-ecPublicKey id-ecPublicKey id-ecPublicKey

Parameters

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

Extensions AuthorityKeyIdentifier (x) (x) (x) (x) SubjectKeyIdentifier (x) / nc (x) / nc (x) / nc (x) / nc KeyUsage c c c c

digitalSignature 0/1 0/1 1 0/1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 0/1

keyEncipherment 0/1 0/1 0/1 0/1 dataEncipherment 0 0 0 0 keyAgreement 0/1 0/1 1 0/1 keyCertSign 1 1 0 0 cRLSign 1 1 0 0 encipherOnly 0 0 0 0 decipherOnly 0 0 0 0

ExtendedKeyUsage

-

-

- 1.3.6.1.5.5.7.3.

9 - OCSPSigning

CertificatePolicies - - - - BasicConstraints c c c c

CA true true false false PathLength 1 0 - -

CRLDistributionPoints (x) / nc (x) / nc (x) / nc (x) / nc

Authority Information Access (OCSP)

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

Cryptographic Algorithm ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Signature Value

Octect-String Octect-String Octect-String Octect-String

Page 66: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Hubject PKI Certificate

Profiles

Cluster: Mobility Operator

Name: V2G Root CA

MO Sub-CA 1 MO Sub-CA 2 Contract Cert

Type: Root Sub Sub/Leaf Leaf tbsCertificate Version 2 (X.509v3) 2 (X.509v3) 2 (X.509v3) 2 (X.509v3)

SerialNumber Integer Integer Integer Integer

Signature ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Issuer Country (x) (x) (x) (x) Organization x x x x Organization Unit (x) (x) (x) (x) Common Name x x x x Domain Component (x) (x) (x) (x)

Validity 40 years 20 years 10 years 1 day - 2 years

Subject Country (x) (x) (x) - Organization x x x x Organization Unit (x) (x) (x) (x) Common Name x x x EMAID Domain Component "V2G" (x) (x) (x)

SubjectPublic KeyInfo

Public Key x X x x Cryptographic Algorithm id-ecPublicKey id-ecPublicKey id-ecPublicKey id-ecPublicKey

Parameters

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

Extensions AuthorityKeyIdentifier (x) (x) (x) (x) SubjectKeyIdentifier (x) / nc (x) / nc (x) / nc (x) / nc KeyUsage c c c c

digitalSignature 0/1 0/1 1 1 nonRepudiation (contentCommitment) 0/1 0/1 1 1

keyEncipherment 0/1 0/1 0/1 1 dataEncipherment 0 0 0 0 keyAgreement 0/1 0/1 0/1 1 keyCertSign 1 1 1 0 cRLSign 1 1 1 0 encipherOnly 0 0 0 0 decipherOnly 0 0 0 0

ExtendedKeyUsage - - - - CertificatePolicies (x) / nc - - - BasicConstraints c c c c CA true true true false PathLength - 1 0 - CRLDistributionPoints (x) / nc (x) / nc (x) / nc (x) / nc

Authority Information Access (OCSP)

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp / location

of the OCSP responder

Cryptographic Algorithm ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Signature Value

Octect-String Octect-String Octect-String Octect-String

Page 67: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Hubject PKI Certificate

Profiles

Cluster: Certificate Installation Service (Prov) Name: Prov Sub-CA 1 Prov Sub-CA 2 Leaf Prof Cert Type: Sub Sub Leaf

tbsCertificate Version 2 (X.509v3) 2 (X.509v3) 2 (X.509v3) SerialNumber Integer Integer Integer

Signature ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Issuer Country (x) (x) (x) Organization x x x Organization Unit (x) (x) (x) Common Name x x x Domain component "V2G" (x) "CPS"

Validity 4 years 1-2 years 2-3 months Subject Country (x) (x) x

Organization x x x Organization Unit (x) (x) (x) Common Name x x x Domain Component (x) (x) (x)

SubjectPublic KeyInfo

Public Key x x x Cryptographic Algorithm id-ecPublicKey id-ecPublicKey id-ecPublicKey

Parameters

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

Extensions AuthorityKeyIdentifier (x) (x) (x) SubjectKeyIdentifier (x) / nc (x) / nc (x) / nc KeyUsage c c c

digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1

keyEncipherment 0/1 0/1 0/1 dataEncipherment 0 0 0 keyAgreement 0/1 0/1 0/1 keyCertSign 1 1 0 cRLSign 1 1 0 encipherOnly 0 0 0 decipherOnly 0 0 0

ExtendedKeyUsage - - - CertificatePolicies (x) / nc - - BasicConstraints c c c

CA true true false PathLength - 0 -

CRLDistributionPoints (x) / nc (x) / nc (x) / nc

Authority Information Access (OCSP)

(x) / nc id-ad-ocsp /

location of the OCSP responder

(x) / nc id-ad-ocsp /

location of the OCSP responder

(x) / nc id-ad-ocsp / location

of the OCSP responder

Cryptographic Algorithm ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Signature Value

Octect-String Octect-String Octect-String

Page 68: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Hubject PKI Certificate

Profiles

Cluster: EV Manufacturer: OEM Provisioning Name: V2G Root CA OEM Sub-CA 1 OEM Sub-CA 2 OEM Prov. Cert. Type: Root Sub Sub Leafs

tbsCertificate Version 2 (X.509v3) 2 (X.509v3) 2 (X.509v3) 2 (X.509v3) SerialNumber Integer Integer Integer Integer

Signature ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Issuer Country (x) (x) (x) (x) Organization x x x x Organization Unit (x) (x) (x) (x) Common Name x x x x Domain Component (x) (x) (x) (x)

Validity 40 years 20 years 10 years Max. 10 years Subject Country (x) (x) (x) -

Organization x x x x Organization Unit (x) (x) (x) (x) Common Name x x x PCID Domain Component (x) (x) (x) (x)

SubjectPublic KeyInfo

Public Key x x x x Cryptographic Algorithm id-ecPublicKey id-ecPublicKey id-ecPublicKey id-ecPublicKey

Parameters

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

ECParameters (namedCurve secp256r1)

Extensions AuthorityKeyIdentifier (x) (x) (x) (x) SubjectKeyIdentifier (x) / nc (x) / nc (x) / nc (x) / nc KeyUsage c c c c

digitalSignature 0/1 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 0/1

keyEncipherment 0/1 0/1 0/1 0/1 dataEncipherment 0 0 0 0 keyAgreement 0/1 0/1 0/1 1 keyCertSign 1 1 1 0 cRLSign 0/1 1 1 0 encipherOnly 0 0 0 0 decipherOnly 0 0 0 0

ExtendedKeyUsage - - - - CertificatePolicies (x) / nc - - - BasicConstraints c c c c

CA true true true false PathLength - 1 0 -

CRLDistributionPoints (x) / nc (x) / nc (x) / nc (x) / nc

Authority Information Access (OCSP)

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP

responder

(x) / nc id-ad-ocsp /

location of the OCSP responder

Cryptographic Algorithm ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

ecdsa-with- SHA256

Signature Value

Octect-String Octect-String Octect-String Octect-String

Page 69: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 70: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 71: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 72: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 73: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 74: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 75: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Page 76: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 77: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 78: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment
Page 80: Hubject ISO 15118 V2G PKI - Certificate Policy · 2019. 9. 25. · digitalSignature 0/1 0/1 1 nonRepudiation (contentCommitment) 0/1 0/1 0/1 keyEncipherment 0/1 0/1 0/1 dataEncipherment

Questions?

[email protected]

Ver.sion n.6 - Äugust 20n9 8uoject Gmo8