Commit 384661b1 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent b496fec4
Loading
Loading
Loading
Loading
+3 −2
Original line number Diff line number Diff line
@@ -1027,12 +1027,12 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
  - RATIONALE: Unnecessary network configuration elements add complexity and increase the potential attack surface. 
  - APPLICABILITY: UC1, UC2, UC3, and UC5

- REFERENCE: 	REQ-PKI-DM-01
- REFERENCE: 	REQ-PKI-DM-02
  - REQUIREMENT: The product shall only maintain configuration data sufficient to provide PKC management functions.
  - RATIONALE: Unnecessary PKC management function configurations (as defined per use case in Annex U) introduce unnecessary complexity and avoidable risks.
  - APPLICABILITY: UC1, UC2, UC3, and UC5

- REFERENCE: 	REQ-PKI-DM-02
- REFERENCE: 	REQ-PKI-DM-03
  - REQUIREMENT: The product shall only maintain and process user data necessary for certificate management (e.g. certificate requests, updates).
  - RATIONALE: For each use case, only user data necessary for the certificate management functions identified in Annex U are required.
  - APPLICABILITY: All use cases.
@@ -2129,6 +2129,7 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
    - Configuration documentation.
    - Assessment records mapping configuration parameters to PKC functions.

### 6.8.2 DM - Secret management
- REFERENCE: ACC-PKI-DM-04
  - OBJECTIVE:
    - Determine whether all key generation operations are performed exclusively by approved Secure Cryptographic Devices (SCDs) or remote Key Management Systems (KMSs) implementing cryptographic mechanisms conformant with Annex K.