GOpenCDR certificate subscriber agreement
What you agree to when you obtain a certificate from the GOpenCDR certificate authority: control of the name, care of the key, public logging, and when a certificate is revoked.
This agreement
This agreement is between Gelhaus Solutions, operating the GOpenCDR certificate authority, and you, whenever you obtain a certificate from it. You accept it when you create an ACME account and agree to the terms of service the ACME directory links to, which is this page. The certificate policy and practice statement sets out how the certificate authority works, and applies to you with this agreement.
What you promise
- You control every name in each request you make, and you keep controlling it for as long as you use a certificate for it.
- What you put in a request is accurate.
- You generated the key pair yourself. You keep the private key secret and under your control, and share it with nobody who is not entitled to act for the names.
- You use a certificate only for TLS server authentication for the names in it, only on servers that serve those names, and only lawfully and within the acceptable use policy.
- You request revocation at once if the private key is or may be compromised, if you lose control of a name in the certificate, or if anything in it becomes inaccurate. You stop using a certificate once it has expired or been revoked.
- You answer promptly when we contact you about a possible compromise or a wrongly issued certificate.
What you accept
- Every certificate is public. It is recorded in the GOpenCDR certificate transparency log with every name in it, and the entry is permanent.
- Only people who installed the GOpenCDR root trust your certificate. It is not part of the public web PKI, and browsers do not trust it by default.
- A certificate lasts at most 45 days. Renew it automatically.
- We revoke for the reasons in the certificate policy and practice statement: among them, when your registration of a name ends or passes to someone else, when a name is withdrawn under the IANA rule, when its TLD leaves GOpenCDR, and when this agreement is broken.
What we do
We issue only after checking your control of each name with DNSSEC-validated lookups and checking its CAA records, we log every certificate before it is used, we revoke within 24 hours of establishing a reason, and we publish revocation lists at least every 24 hours.
Everything else
Certificates are free. No warranty is given and no service level applies. For what is given away, liability is limited to intent and gross negligence (Section 521 BGB), and otherwise it is as the general terms of service set out. You may close your ACME account at any time; a certificate already issued stays valid until it expires unless you or we revoke it. German law applies.