SII
acronymcryptographysecurity
Stands for: Subscriber Identity Information
Reusable subscriber-identity data in the certificate issuance process.
Subscriber Identity Information refers to previously validated details about a certificate subscriber that a CA may reuse for a limited time. Like DCV, the window for reusing SII has been tightened by industry baseline rules.
Subscriber identity information in certificate issuance is validated data about an organization that can be reused across multiple requests rather than re-verified each time. It exists because organization validation is slow and largely repeats the same checks.
The security question it raises is freshness. Reusing a validation means a certificate can be issued against an organization's status as it was some time ago, and the industry's rules therefore cap how long such data may be relied upon. That cap has tightened repeatedly as the tension between issuance speed and validation currency has been argued out, and it is one of the reasons automated domain validation with short lifetimes has displaced organization validation for most purposes.
Also known as: sii