Certification Policy for key authentication and key encipherment certificates
 
   
 

  Within the context of the remote declaration and remote regulation project of VAT, MINEFI has defined a Certification Policy with which the Certification Authority must comply.
A checking procedure is set up to ensure that Certification Authorities comply with this policy. This is know as accreditation.

In this context, the Certification Policy of SG TRUST SERVICES aims at conforming to the document called "Procedures and Policies of Certification of Keys (PC²)" issued by the Interdepartmental Commission for Security of Information Systems (Commission Interministérielle Sécurité des Systèmes d'Information) (CISSI), for PRIS V1 of MINEFI and the RFC 2527 document of the IETF.

The Certification policy of SG Trust Services is periodically reviewed mainly to ensure its compliance with standards and recommendations issued by the Ministry of Economy and Finance (Ministère de l'Economie et des Finances) and by the Audit and Recognition Board (l'Entité d'Audit et de Référencement), update the list of applications related to the PC and adapt to technological and contractual developments.

You will find below the Certification Policy of SG TRUST SERVICES that conforms to PRIS V1 of Minefi :

 

You will find below the previous Certification Policy of SG TRUST SERVICES :

 

In case of violation, or suspicion of violation of your certificate you must revoke it immediately.

Revocation requests can be made online (on our website accessible 24 hours a day), by phone* (Client Service on the phone number +33(0) 2 54 44 71 07), and by post, e-mail or fax addressed to our Client Service (Contact Page). They can also be made at Société Générale branch offices during business hours.

*Outside business hours, the phone request is taken by an answering machine (which records the request).

If your revocation request is not recorded online, you have to give the following information when making this request:

  • The family name and first name of the Subscriber,
  • e-mail of the Subscriber,
  • Subscriber Identification Code,
  • The application which it accesses,
  • Function of the certificate: "nominal" or "backup".