Commit 29cb8677 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Minor

parent 9d1ce03c
Loading
Loading
Loading
Loading
+8 −2
Original line number Diff line number Diff line
@@ -556,15 +556,21 @@ As a result, users of these PKI solutions do not have the same deployment flexib

### 4.6.3  Open or public PKI for critical entities (UC3)

PKI product used to support certification management services (registration, certificate generation, revocation and status management) provided within very large multi-site company or provided by a CA to the public, and where a compromise carries a significant risk of impact to the security of remote or unknown users, other products, networks or services, or to the health, security or safety of the public.

Such PKIs are deployed in highly controlled environments, including robust physical and logical security measures, along with strict policies and processes.

- EXAMPLE 1: Products deployed for a PKI used in large enterprise or critical entities (e.g, eIDAS where in the context of the present document ETSI EN 319 411-1 [] defines requirements on security hardware elements of the PKI and requirement of software elements of the PKI for use in eIDAS).

### 4.6.4 Product for use in Open or Public basic PKI (UC4)

PKI product used to support certification services provided within very large multi-site company or provided by a CA to the public, and where a compromise carries a significant risk of impact to the security of remote or unknown users, other products, networks or services, or to the health, security or safety of the public.
PKI product used to support certification services (certificate generation, revocation and status management) provided within very large multi-site company or provided by a CA to the public, and where a compromise carries a significant risk of impact to the security of remote or unknown users, other products, networks or services, or to the health, security or safety of the public. 

Such PKIs are deployed in highly controlled environments, including robust physical and logical security measures, along with strict policies and processes.

- EXAMPLE 1: Products deployed for Trust services. Software used to issue certificates for trust services including those used in electronic attribute attestation.

### 4.6.5 Product for use in multi-authority PKI
### 4.6.5 Product for use in multi-authority PKI (UC5)
In general terms the multi-authority model separates the entity responsible for authentication from the entity responsible for authorisation of specific services, in like manner to the model of Kerberos [[i.5](#_ref_i_5)] but applied to a public key system.

The multi-authority PKI is intended to combine multiple authorities in a single (extended) domain, sharing resources, and enforcing minimisation of identifying data. In like manner to Kerberos the certificate model in multi-authority PKI enables anonymous or pseudonymous proof of authority. The product in multi-authority PKIs is expected to be able to generate and distribute signed attestations of authority, to verify any received attestation of authority, and to maintain the status of stored public keys.