@@ -793,11 +793,15 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
### 5.7.2 Certificate signing
- REFERENCE: REQ-PKI-INT-006
- REQUIREMENT: The product shall only create certificate siganture by means of a Secure Cryptographic Device (SCD) appropriate for this use.
- REFERENCE: REQ-PKI-INT-06
- REQUIREMENT: The product shall create certificate signature only by means of a Secure Cryptographic Device (SCD).
- RATIONALE: To ensure trust the product software must rely on secure and valid key creation and management systems accessible only to authorised users provided by hardware security devices. It covers key tampering and disclosure threats: T_GEN01 to T_GEN08, T.Stored_Certificates_Tampering.
- APPLICABILITY: UC2, UC3, UC4, UC5
- REFERENCE: REQ-PKI-INT-07
- REQUIREMENT: The cryptographic mechanisms used to create certificate signature shall be as stated in Annex K.