@@ -1233,22 +1233,14 @@ To limit certificate forgery or misuse of certificate content, this section defi
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses of the basic response type: UC1 and UC2.
- NOTE: An OCSP responder is required to be capable to emit OCSP responses of the basic type by RFC 6960 [\[i.3\]](#_ref_i.3).
### 5.12.3 Certificate renewal
### 5.12.4 Certificate re-key
- REFERENCE: REQ-PKI-EMM-014
- REQUIREMENT: Requirement GEN-6.3.6-10 contained in ETSI EN 319 411-1 [\[6\]](#_ref_5) shall apply.
- NOTE:
- RATIONALE: The product should never issue a certificate with foreseeable insufficient cryptographic security. The product should never issue a certificate for a key associated to any kind of security compromission.
- APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate renewal.
### 5.12.3 Certificate re-key
- REFERENCE: REQ-PKI-EMM-15
- REFERENCE: REQ-PKI-EMM-14
- REQUIREMENT: In case of certificate re-key, any modified certified names or attributes shall be validated and updated registration information shall be recorded.
- RATIONALE: The product should never issue a certificate without having validated all its certified names and attributes at some point in time. The product should possess accurate registration information regarding certificates it re-keys.
- APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate re-key.