@@ -2929,7 +2929,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1 INT_CONF-1
**Objective:**Protect the management actions and the interaction with the system enabling only secure channels.
**Objective:**All management actions and interactions between the product and the managed elements use only secure channels.
**Preparation:**
@@ -2953,9 +2953,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;
### 6.8.1.1 INT_CONF-2
### 6.8.1.2 INT_CONF-2
**Objective:**Prevent the use of old keys.
**Objective:**The configuration data provided from the product to the managed element is protected against tampering and its integrity can be verified.
**Preparation:**
@@ -2971,10 +2971,10 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
**Verdict:**
1. Pass, and the documented configuration transfer upholds the integrity of the configuration
2. and if the managed element does not have access to other configurations configured in the system
3. the device detects the alteration of configuration when it is possible to perform.
1. Fail otherwise.
1. Pass, if and the documented configuration transfer upholds the integrity of the configuration
2. and the managed element does not have access to other configurations configured in the system
3.and the device detects the alteration of configuration.
4. Fail otherwise.
**Supporting Evidence:**
@@ -2985,7 +2985,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1.3 INT_CONF-3
**Objective:**Prevent the use of old keys.
**Objective:**The product supports authenticity requests received from its management elements.
**Preparation:**
@@ -2999,7 +2999,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
**Verdict:**
1. Pass, if the element can cryptographically verify the product.
1. Pass, if the product supports the managed element’s cryptographic authenticity verification.
2. Fail otherwise.
**Supporting Evidence:**
@@ -3013,7 +3013,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.1 INT_ROTATE-1
**Objective:** When employees and administrators roles change, the related keys shall change accordingly.
**Objective:** When employees and administrators roles change, the related keys are rotated.
**Preparation:** None
@@ -3025,7 +3025,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
**Verdict:**
1. Pass, if key rotation can be made on demand
2. and the instructed rotation policy is fit for the foreseeable use of the product
2. and the instructed rotation policy matches with the foreseeable use of the product
3. and the keys can be initialised when the product is taken into use for a first time or after a reset to factory settings.
4. Fail otherwise.
@@ -3035,22 +3035,22 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.2 INT_ROTATE-2
**Objective:** New devices can be initialised with the shared secrets and trust anchors.
**Objective:** New managed elements are initialised with shared secrets, trust anchors and with the product support.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
2. Have a managed element to test with.
2. Have an untrusted network element to test with.
**Activities:**
1. Study the technical documentation.
2. Reset the managed element to factory defaults.
3.Attach the element into the system.
3.Integrate the untrusted element as new managed element into the network.
**Verdict:**
1. Pass, if a managed element has the cryptographical keys and trust structures in use after the test actions.
1. Pass, if a integrated managed element has the cryptographical keys and trust structures in use after the test actions.