Short Form Certificate Policy

Medicare Australia Site CertificatesCommunitiesof

Interest (CoI) Certificate Policy (CP)for Site Certificates issued under theMedicareAustraliaOrganisation Certification

Authority (Medicare Australia OCA)V1.6

February 2007


This document contains information protected by copyright.© Commonwealthof Australia

Thiswork is copyright.


Medicare Australia

Locked Bag 6666

TuggeranongDC ACT 2901


This Document has been authorised by the MedicareAustralia Policy Management Authority:


General Manager or nominee, Information Technology Services Division, Medicare Australia


This is the Certificate Policyfor Site Certificates issuedto practicesand entities known to Medicare Australia (for example, government departmentsand agencies; health and welfare services providers) to enable them to conduct secure transactionsand data exchange with Medicare Australiaand other parties in relationto programs authorised orapproved by

Medicare Australia orwithin an entity’sCommunityof Interest recognised by Medicare Australia.

The document is structuredand numbered accordingto the GatekeeperShortFormCertificate

Policy Template.

This CPshould be read in conjunction with the Medicare Australia Organisation Certification

Authority Certification Practice Statement (Medicare Australia OCACPS).


Site CertificatemeansaCertificate issued under this CP.

Site means:

a) the site location of any practice registered by Medicare Australia for a Medicare Australia program.The practice may bereferred toas a RegisteredMedicare Australia Practiceor practiceand includes Pharmacies andagedcare providers (however described); and:

b) any site of anentity, where that entity is recognised by Medicare Australia as a

member of aMedicare Australia recognisedCommunity of Interestand is known to

Medicare Australiaand where MedicareAustralia is the Relationship Organisation.

Certificate Policy Clauses

CP Identification

Certificates issued under this CP shall bear the PolicyOID:

(where “174030967” is the last 9 digits of Medicare Australia’s Australian Business Number).


Practices andentities whowish to undertakesecure electronic transmissions:

•with Medicare Australia and/or access to data held byMedicare Australia;and / or

•within a Community of Interest

may require a site certificate (Site Certificate).

TheRelationship model (also referred to as Known Customer PKI) streamlines the enrolment of practices andentities for a Site Certificate.

The Site Certificate hasa unique PolicyOID.

TheRelationship Organisation for this CPis MedicareAustralia. TheRelationship Organisation Units (ROU) are:

•program area(s) in Medicare Australia responsible forprogramsaccessible by practices using Site Certificates; and

•entities whoare membersof a Community of Interest.

TheRelationship Organisation Unit Operators (ROUOs) are:

•Medicare Australia personnel (for Medicare Australia)who accept and manage the registrationof practices); or

•personnel of the entities who are members of the Community of Interest who accept

and manage the registration of entities

to participatein a programusing the practice or entity’s Site Certificate.

1.1 PKI Participants

1.1.1Certification Authority

All Certificates issued under this CP shallbe produced by the Medicare AustraliaOrganisation

Certification Authority (Medicare Australia OCA).

Refer to theMedicare Australia OrganisationCertification AuthorityPractice Statement

(Medicare Australia OCA CPS) for further information on applicablepractices andprocedures for

Certificates issued under this CP.

1.1.2. Relationship Organisation

Medicare Australia is theRelationship Organisation (Medicare Australia RO) in the Health Sector


1.1.3. Relationship Organisation Unit

Thereare separately identified Relationship Organisation Units (ROUs) within the Medicare Australia RO,usuallyone ROU for eachCommunityof Interest(CoI) in the Health Sector PKI operated by Medicare Australia.

TheROU hasresponsibilities in the CoIinmanaging the Subscribers in that CoI.

The various program areas in MedicareAustraliaarethe ROUs forthe participating practices. The entities in a MedicareAustralia recognisedCoI are the ROUs for the participating entities.


Certificate ControllersareMedicare AustraliaRO personnel with responsibilitiesfor management of Certificates.

All CertificateControllers operating underthis CP are duly authorised representatives of

Medicare Australia.

Certificate Controllers maynot be located within the various program areas ofMedicare Australia. Certificate ControllersareMedicare Australia personnelwho may belocated outside of the program areas.

1.1.5Relationship Organisation Unit Operators

Relationship OrganisationUnit Operators (ROUOs) who areMedicare Australiapersonnel within the relevantprogram CoIare located within Medicare Australia.

ROUOs who are personnelof an entity within a relevant CoI are located withinthat entity. ROUOs withinany CoI arenot Certificate Controllers.

All ROUOs operate inaccordance with the processes and procedures set out inthe Medicare

Australia OCA CPS and this CP.

1.1.6. Subscribers

All Subscribers for Site Certificates shall be either:

•practices registered with aMedicare Australia program and knownto MedicareAustralia assuch according to an application for participation ina Medicare Australia program,or

•an entity which is knownto Medicare Australia and isa member ofa recognised

Medicare Australia Community of Interest.

A person, who is authorised by a practice or entitytobind the practice or entity, must enter into the Subscriber agreement for a SiteCertificatewhich is knownas theMedicareAustralia CommunitiesofInterestSiteCertificateTermsandConditionsofUse.

1.1.7. Relying Parties

TheRelying Party under this CP, in relation toMedicare Australia program CoIs, is Medicare

Australia,as receiver of transactionssecured using the Site Certificates.

TheRelying Party under this CP, in relation to entitiesknown to Medicare Australia and who are in a recognised Medicare Australia CoI, is theother entity in the CoI who is thereceiver of transactionssecured usingthe Site Certificates.

There is noRelying Party Agreement under this CP.

Parties who rely on Certificates issued under this CPand who do not have a written agreement with Medicare Australia relating to transactionswith Medicare Australia,or who undertake transactionsthat are notauthorised orapprovedbyMedicare Australia relyonsuch certificates at theirown risk.

1.2Certificate Use

1.2.1Appropriate Certificate Uses

Key PairsandCertificates issued under this CP aretobe used by Sites to securetransactions for programsandservices authorisedor approved by Medicare Australia.

1.2.2Prohibited Certificate Uses

Thereare noprohibited certificate uses.Partiesusingthe Site Certificates for any transaction other than transactions authorisedor approved by Medicare Australia do so attheir own risk.

1.3Definitions and Acronyms

Definitionsand Acronymsare in the Health Sector PKI Glossary at


2.1Naming of Subscribers

Subscribers(termed ‘Certificate Subjects’in the x.509definition) under this CP will be named (and the uniqueness of their nameswill be assured) consistent with the name recognised by Medicare Australia throughits relationship with the Subscriber.This may include the name by which Medicare Australia has recognisedthe entityasa member ofa CoI or the name under which the entity is registered asa Subscriber.

2.2Identification and authentication of the Subscriber at registration

Subscribers under this CPwill be identified and authenticated by:

•Medicare AustraliaROUs responsible for registeringpractices forMedicare Australia programsandservices; or

•In each CoI,the entity’sROU responsible forregistering that entityfor a Site Certificate in the HealthSector PKIoperated by Medicare Australia.

2.3Identification and authentication of the Subscriber at renewal

Subscribers under this CP shall be identifiedand authenticatedand the Certificate renewed automaticallyprovided that

•if the Site isa Registered Medicare AustraliaPractice, its registrationstatus with the relevantROU has not changed, or

•if the Site is an entity recognised by Medicare Australia in aMedicare Australia

CoI, its registrationstatuswith that entity’s ROU hasnot changed.

Note:all certificate renewals under thisCP involve re-keying.

2.4Identification and authentication of revocation request

Revocation ofcertificates under this CP shall only be requested by:

•ROUOs in theevent that the Subscriberbecomes ineligible to remain asa Registered Medicare Australia Practice or entity recognised by Medicare Australia as a member ofa Medicare Australia recognised CoI; or

•The Subscriber by writtennotice;or

•Certificate Controllers.


3.1.Certificate creation

3.1.1. Enrolment process and responsibilities

Wherea Siteis a Registered Medicare Australia Practice, theSite may be enrolled automatically for Certificates by Certificate Controllerson the basis of that registration.

Wherea Siteis a not aRegisteredMedicare AustraliaPractice, thepracticemayapply to the relevantROU for the CoI of the Medicare Australia program orservice to be registered for that program orservice and to be enrolled for Site Certificates when registration asa Registered Medicare Australia Practice occurs.

Wherea Siteis a not aRegisteredMedicare AustraliaPractice, theentity, beinga member ofa Medicare Australia CoIandresponsible for thatSite, may apply tothe MedicareAustralia RO Certificate Controllersto be enrolled forSite Certificates.

All applications madea practice and an entity arethe responsibilityof the practice or entity through its authorised contactperson (however described).

3.1.2. Publication of the certificate by the CA

Certificates issued under this CP will bepublished in the HealthcarePublic Directory.

Revocation statusof Certificates issuedunder this CPwill be published in the Healthcare Public


3.2.Key Pair and Certificate Usage

3.2.1 Key pair generation and installation

The Subscriber Key Pairsand Certificates issued under this CP shallbe generated by a

Certificate Controller usingaccreditedsoftware.

Thesigning key and Certificate will bestored in a password protected PKCS#12 file separate from the encryption key and Certificate.These PKCS#12 files arestored in electronic medium1 and posted as instructed by the ROUO.

1‘electronicmedium’includesfloppy disk.CD or othermediuminwhich data can bestored electronically.

A passphrase to access the keysand Certificates will be generated and postedseparately to the


3.3.Certificate renewal

Certificates issued under this CP shall be renewedautomatically bythe Certificate Controllers. In the case ofa RegisteredMedicare Australia Practice, the Certificate shall be renewed

automaticallyafter checking its status oron advice from the ROUOs, provided the status of the

Registered Medicare AustraliaPractice has not changed.

In the case ofan entity, the Certificate shall be renewed automatically after checking its status or on advice from the ROUOs, provided the status ofthe entity has not changed.

Refer to clause 2.3 for details of identificationand authentication.

3.4.Certificate revocation

Certificates issued under this CP may be revoked byMedicare Australia in its absolute discretion, including but not limited to:

•after loss, destruction or theft of the Site Certificate;

•intheeventofde-registrationofthepractice(howeverdescribed)whetherinrelation toparticipationinanyMedicareAustraliaprogramornot;

•intheeventofanyApprovals(howeverdescribed)relatingtothepracticebeing cancelledbyMedicareAustralia;

•in the eventany ApprovalNumber(s) (however described) relatingto the practice being cancelled by Medicare Australia;

•in the event that theentityceasesto exist or be recognised by Medicare Australia or ceases tobe a memberof a Medicare Australia recognised CoI.

3.5Certificate status services


Detailsof Operational Characteristicsare not provided.

3.5.2Service availability

Service availability for theCertificateRevocation List(CRL) issubstantially 24 x7 at

3.5.3Optional features

Detailsof Optional Features are not provided.



All CertificateControllers under this CP shall be authorised representatives ofMedicare


4.2Logical and Technological controls

Certificate requests will be processed bythe authorised CertificateControllers ofMedicare

Australia in accordancewith the securityprovisions ofthe Medicare Australia OCA CPS.

4.3Physical controls

Certificate requests will be processed byAuthorised Certificate Controllers inaccordancewith the security provisionsof the MedicareAustralia OCACPS.

4.4Business continuity of the RelationshipOrganisation

As MedicareAustralia (theRelationship Organisationunder this CP) is astatutory agency under the MedicareAustralia Act1973,its continuation depends on continuance in force of the Medicare Australia Act1973or by otherActs ofthe Commonwealth Parliament made pursuant to government policy.

Changes in legislation or government policy willprovide for business continuityof the RO in accordance with policy as determined bythe government.

4.5Relationship Organisation termination

As MedicareAustralia isastatutoryagency under theMedicareAustraliaAct1973,its termination or change of entity status is through amendment to the MedicareAustraliaAct1973or by other Acts ofthe CommonwealthParliament made pursuantto changes ingovernment policy.


5.1 Certificate profile – Site Encipherment Certificate

Field / Content / Mandatory / Critical*
1.X.509v1Field / N/A
1.1.Version / V3 / M
1.2.SerialNumber / Apositiveintegerthatuniquelyidentifies
theCertificate. / M
1.3.SignatureAlgorithm / SHA-1RSA,
signingalgorithm. / M
1.4.IssuerDistinguishedName / M
1.4.1.Country(C) / AU / M
1.4.2.Organization(O) / GOV / M
1.4.3.OrganizationUnit(OU) / MedicareAustralia / M
1.4.3CommonName(CN) / MedicareAustraliaOrganisation
CertificationAuthority / M
1.5.1.NotBefore / ThedatethattheCertificateisvalidfrom
(systemtimeatcertificateissuance). YYMMDDHHMMSSZencodedas
UTCTimefordatesupto2049and encodedasGeneralizedTimefordatesin
2050orlater. / M
1.5.2.NotAfter / ThedatethattheCertificateisvaliduntil.
5 yearsfromStartValidity,i.e.certificate issuance.
YYMMDDHHMMSSZencodedas UTCTimefordatesupto2049and encodedasGeneralizedTimefordatesin
2050orlater / M
1.6.1.Country(C) / AU / M
1.6.2.State(St) / <STATE> / M
1.6.3Locality(L) / <SuburbName> / M
1.6.4.Organization(O) / <TradingName<Locality / M
1.6.5.OrganisationUnit(OU)) / <TradingName<Locality / M
1.6.6.CommonName(CN) / <TradingName<Locality:RANumber / M
1.7.SubjectPublicKeyInfo / RSAPublicKeyof2048bits. / M
2.1.AuthorityKeyIdentifier / M / Non- Critical
2.1.1.KeyIdentifier / SHA-1hash(60bits)oftheIssuer's
2.1.2.AuthorityCertIssuer / Notpresent
2.1.3.AuthorityCertSerialNumber / Notpresent
2.2.SubjectKeyIdentifier / SHA-1hash(60bits)oftheSubject's
publickey. / M / Non- Critical
2.3.KeyUsage / M / Critical
2.3.1.DigitalSignature / NOTSET
2.3.2.NonRepudiation / NOTSET
2.3.3.KeyEncipherment / SET
2.3.4.DataEncipherment / NOTSET
2.3.5.KeyAgreement / NOTSET
2.3.6.KeyCertificateSignature / NotSelected
2.3.7.CRLSignature / NotSelected
2.4.ExtendedKeyUsage / Notapplicable / Non- Critical
Non- Critical
2.5.1.PolicyIdentifier / / UserNotice / CertificatesissuedunderthisCPmustbe
reliedonbyentitieswithinthe Communityof Interest,unlessotherwise agreed,andnotforpurposesotherthan thosepermittedbythisCP. / CPSURI
Field / Content / Mandatory / Critical* /
2.6.SubjectAlternateNames / Non- Critical
2.6.1.rfc822Name / <emailaddress> / O
2.7.1.SubjectType / NotCA / Critical
2.7.2.PathLengthConstraint / Notpresent
2.8.1.AccessDescription / Notpresent / On-lineCertificateStatusProtocol
( / Non- Critical / URL=
2.9.1URL /
%3DMedicare%20Australia%2Cc%3DAU / Non- Critical
3.0.1 GenericIA5String:
(OID= / RANumber / M
3.0.2 GenericIA5String:
(OID= / HealthcareProviderIdentifier / O
3.0.3 GenericIA5String:
(OID= / MedicareIdentifier / O
3.0.4 GenericIA5String:
LocationID (OID= / LocationID / O
3.0.5 GenericIA5String:
(OID= / PharmacyApprovalNumber / O

5.2 Certificate profile–Site Signing Certificate

Field / Content / Mandatory / Critical*
1.X.509v1Field / N/A
1.1.Version / V3 / M
1.2.SerialNumber / Apositiveintegerthatuniquelyidentifies
theCertificate. / M
1.3.SignatureAlgorithm / SHA-1RSA,
signingalgorithm. / M
1.4.IssuerDistinguishedName / M
1.4.1.Country(C) / AU / M
1.4.2.Organization(O) / MedicareAustralia / M
1,4,3,OrganizationUnit(OU) / MedicareAustralia / M
1.4.4CommonName(CN) / MedicareAustraliaOrganisation
CertificationAuthority / M
1.5.1.NotBefore / ThedatethattheCertificateisvalidfrom
(systemtimeatcertificateissuance). YYMMDDHHMMSSZencodedas
UTCTimefordatesupto2049and encodedasGeneralizedTimefordatesin
2050orlater. / M

2TheseCertificate extensionOIDreferencesare expectedto be commontoall CoI Certificate Policies, and may haveapplicability to this CoI.

Field / Content / Mandatory / Critical*
1.5.2.NotAfter / ThedatethattheCertificateisvaliduntil.
5 yearsfromStartValidity,i.e.certificate issuance.
UTCTimefordatesupto2049and encodedasGeneralizedTimefordatesin
2050orlater / M
1.6.1.Country(C) / AU / M
1.6.2.State(St) / <STATE> / M
1.6.3.Locality(L) / <SuburbName> / M
1.6.4.Organization(O) / <TradingName<Locality / M
1.6.5.OrganisationUnit(OU)) / <TradingName<Locality / M
1.6.6.CommonName(CN) / <TradingName<Locality:RANumber / M
1.7.SubjectPublicKeyInfo / RSAPublicKeyof2048bits. / M
2.1.AuthorityKeyIdentifier / M / Non- Critical
2.1.1.KeyIdentifier / SHA-1hash(60bits)oftheIssuer's
2.1.2.AuthorityCertIssuer / Notpresent
2.1.3.AuthorityCertSerialNumber / Notpresent
2.2.SubjectKeyIdentifier / SHA-1hash(60bits)oftheSubject's
publickey. / M / Non- Critical
2.3.KeyUsage / M / Critical
2.3.1.DigitalSignature / SET
2.3.2.NonRepudiation / NOTSET
2.3.3.KeyEncipherment / NOTSET
2.3.4.DataEncipherment / NOTSET
2.3.5.KeyAgreement / NOTSET
2.3.6.KeyCertificateSignature / NotSelected
2.3.7.CRLSignature / NotSelected
2.4.ExtendedKeyUsage / Notapplicable / Non- Critical
Non- Critical
2.5.1.PolicyIdentifier / / UserNotice / CertificatesissuedunderthisCPmustbe
reliedonbyentitieswithinthe Communityof Interest,unlessotherwise agreed,andnotforpurposesotherthan thosepermittedbythisCP. / CPSURI /
2.6.SubjectAlternateNames / Non- Critical
2.6.1.rfc822Name / <emailaddress> / O
2.7.1.SubjectType / NotCA / Critical
2.7.2.PathLengthConstraint / Notpresent
2.8.1.AccessDescription / Notpresent / On-lineCertificateStatusProtocol
( / Non- Critical / URL=
2.9.1URL /
%3DMedicare%20Australia%2Cc%3DAU / Non- Critical

3TheseCertificate extensionOIDreferencesare expectedto be commontoall CoI Certificate Policies, and may haveapplicability to this CoI.

Field / Content / Mandatory / Critical*
3.0.1 GenericIA5String:
(OID= / RANumber / M
3.0.2 GenericIA5String:
(OID= / HealthcareProviderIdentifier / O
3.0.3 GenericIA5String:
(OID= / MedicareIdentifier / O
3.0.4 GenericIA5String:
LocationID (OID= / LocationID / O
3.0.4 GenericIA5String:
(OID= / PharmacyApprovalNumber / O

5.3 Medicare Australia OCA CRL Profile

Field / Content / Mandatory / Critical*
1.X.509v1Field / N/A
1.1.Version / V2 / M
1.2.SignatureAlgorithm / sha1RSA / M
1.3.IssuerDistinguishedName / M
1.3.1.Country(C) / AU / M
1.3.2.Organization(O) / GOV / M
1.3.3.OrganisationalUnit(OU) / MedicareAustralia
1.3.3.CommonName(CN) / MedicareAustraliaOrganisation
CertificationAuthority / M
1.4Validity / M
1.5CRLNumber / M
2.1.AuthorityKeyIdentifier / M / Non- Critical
2.1.1.KeyIdentifier / SHA-1hash(60bits)oftheIssuer’s
Frequencyofissuing / 60minutes
GracePeriod / 60minutes

5.4 Medicare Australia OCA OCSP Profile

Field / Content / Mandatory / Critical*
1.X.509v1Field / N/A
1.1.Version / V3 / M
1.2.SerialNumber / UniquevalueassignedbytheIssuing
CA / M
1.3.SignatureAlgorithm / SHA-1withRSASignature / M
1.4.IssuerDistinguishedName / M
1.4.1.Country(C) / AU / M
1.4.2.Organization(O) / GOV / M
1.4.3.OrganisationalUnit(OU) / MedicareAustralia
1.4.4.CommonName(CN) / MedicareAustraliaOrganisation
CertificationAuthority / M
1.5.Validity / 5years
1.5.1.NotBefore / Issuedate / M
Field / Content / Mandatory / Critical*
1.5.2.NotAfter / Expirydate / M
1.6.1.Country(C) / AU / M
1.6.2.Organization(O) / GOV / M
1.6.3.OrganizationalUnit(OU) / MedicareAustralia
1.6.4.CommonName(CN) / MedicareAustraliaOCAOCSP
Responder / M
1.7.SubjectPublicKeyInfo / PublicKeyencodedinaccordance
withRFC2459& PKCS#1-2048bits / M
2.1.AuthorityKeyIdentifier / SHA-1hash(60bits)oftheIssuer’s
publickey / M / Non- Critical
2.1.1.KeyIdentifier / TheKeyIdentifieroftheIssuerof this
2.1.2.AuthorityCertIssuer / Notpresent
2.1.3.AuthorityCertSerialNumber / Notpresent
2.2.SubjectKeyIdentifier / SHA-1hash(60bits)oftheSubject's
publickey / M / Non- Critical
2.3.KeyUsage / M / Critical
2.3.1.DigitalSignature / SET
2.3.2.NonRepudiation / NotSelected
2.3.3.KeyEncipherment / NotSelected
2.3.4.DataEncipherment / NotSelected
2.3.5.KeyAgreement / NotSelected
2.3.6.KeyCertificateSignature / NotSelected
2.3.7.CRLSignature / NotSelected
2.4.ExtendedKeyUsage / Non- Critical
2.4.1.OCSPSigning /
2.5.1.PolicyIdentifier / Notpresent / Notpresent / Notpresent / Notpresent / Notpresent
2.6.SubjectAlternateNames / Non- Critical
2.6.1.rfc822Name / NA
2.7.1.SubjectType / EndEntity / N/A
2.7.2.PathLengthConstraint / Notpresent
2.8.1.AccessDescription / Notpresent / Notpresent / Non- Critical / Notpresent