@@ -1027,12 +1027,12 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- RATIONALE: Unnecessary network configuration elements add complexity and increase the potential attack surface.
- APPLICABILITY: UC1, UC2, UC3, and UC5
- REFERENCE: REQ-PKI-DM-01
- REFERENCE: REQ-PKI-DM-02
- REQUIREMENT: The product shall only maintain configuration data sufficient to provide PKC management functions.
- RATIONALE: Unnecessary PKC management function configurations (as defined per use case in Annex U) introduce unnecessary complexity and avoidable risks.
- APPLICABILITY: UC1, UC2, UC3, and UC5
- REFERENCE: REQ-PKI-DM-02
- REFERENCE: REQ-PKI-DM-03
- REQUIREMENT: The product shall only maintain and process user data necessary for certificate management (e.g. certificate requests, updates).
- RATIONALE: For each use case, only user data necessary for the certificate management functions identified in Annex U are required.
- APPLICABILITY: All use cases.
@@ -2129,6 +2129,7 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
- Configuration documentation.
- Assessment records mapping configuration parameters to PKC functions.
### 6.8.2 DM - Secret management
- REFERENCE: ACC-PKI-DM-04
- OBJECTIVE:
- Determine whether all key generation operations are performed exclusively by approved Secure Cryptographic Devices (SCDs) or remote Key Management Systems (KMSs) implementing cryptographic mechanisms conformant with Annex K.