Commit 0b9d9e44 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Removing certificate renewal requirement not applicable to product.

parent 0cbc3df0
Loading
Loading
Loading
Loading
+3 −11
Original line number Diff line number Diff line
@@ -1233,22 +1233,14 @@ To limit certificate forgery or misuse of certificate content, this section defi
  - APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses of the basic response type: UC1 and UC2.
  - NOTE: An OCSP responder is required to be capable to emit OCSP responses of the basic type by RFC 6960 [\[i.3\]](#_ref_i.3).

### 5.12.3 Certificate renewal
### 5.12.4 Certificate re-key

- REFERENCE: REQ-PKI-EMM-014
  - REQUIREMENT: Requirement GEN-6.3.6-10 contained in ETSI EN 319 411-1  [\[6\]](#_ref_5) shall apply.
  - NOTE: 
  - RATIONALE: The product should never issue a certificate with foreseeable insufficient cryptographic security. The product should never issue a certificate for a key associated to any kind of security compromission.
  - APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate renewal.

### 5.12.3 Certificate re-key

- REFERENCE: REQ-PKI-EMM-15
- REFERENCE: REQ-PKI-EMM-14
  - REQUIREMENT: In case of certificate re-key, any modified certified names or attributes shall be validated and updated registration information shall be recorded.
  - RATIONALE: The product should never issue a certificate without having validated all its certified names and attributes at some point in time. The product should possess accurate registration information regarding certificates it re-keys.
  - APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate re-key.

### 5.12.3 Certificate modification
### 5.12.5 Certificate modification

  - REFERENCE: REQ-PKI-EMM-16