An improved certificate issuing system may comprise a novel arrangement
for expressing certificate issuing policy. The policy may be expressed in
a human-readable policy expression language and stored for example in a
file that is consumed by a certificate issuing system at runtime. The
policy may thus be easily changed by altering the digital file. Certain
techniques are also provided for extending the capabilities of the
certificate issuing system so it may apply and enforce new policies.