- RATIONALE: The same public key may not be used for signature verification, and encryption or key agreement. Only valid certifcates as defined by the PKI service provider policies shall be generated by the product.
- APPLICABILITY: All use cases.
- APPLICABILITY: U2, UC3, UC4, UC5.
- REFERENCE: REQ-PKI-EMM-07
- REQUIREMENT: The product shall verify that the prospective certificate subject possesses the private key that corresponds to the public key in the certificate request before issuing a certificate, unless the public/private key pair was generated by the product and never left the certificate issuance service.