This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (j).
- REFERENCE: REQ-PKI-MAS-01
- REQUIREMENT: TODO The product shall only implement the interfaces identified in clause 4.x.y.
- REQUIREMENT: TODO Only interfaces identified for each use case in Annex U shall be implemented.
- RATIONALE: XXX
- NOTE:XXX
- APPLICABILITY: XXX
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-MAS-02
- REQUIREMENT: TODO Where the product is in scope of EN 303 645 [] the provisions of clause 4.6 of EN 303 645 shall apply.
@@ -1194,7 +1193,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
- RATIONALE: The product shall provide accurate and integrity protected certificates statues using the standardised CRL format ensuring integrity of revocation list and conformity to the product service provider chosen policies.
- APPLICABILITY: Where the product has a certificate status service, issuing CRLs: UC1 and UC2.
- REFERENCE: REQ-PKI-EMM-010
- REFERENCE: REQ-PKI-EMM-10
- REQUIREMENT: TODO(Specify that it is for CRL?) The product shall require authorized users to specify the set of acceptable values for the following fields and extensions:
- issuer;
- issuerAltName;
@@ -1203,7 +1202,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
- APPLICABILITY: Where the product has a certificate status service, issuing CRLs: UC1 and UC2.
- NOTE: The issuerAltName may be absent from the profile if issued certificates do not use it.
- REFERENCE: REQ-PKI-EMM-011
- REFERENCE: REQ-PKI-EMM-11
- REQUIREMENT: The product shall implement an OCSP response profile and shall ensure that issued OCSP responses are consistent with that profile.
- RATIONALE: The product shall provide accurate certificates statusas defined by the service provider chosen policies.
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses.
@@ -1213,7 +1212,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
- RATIONALE: The product shall provide accurate certificates statusas defined by the service provider chosen policies.
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses, not restricted to the basic response type: UC1 and UC2.
- REFERENCE: REQ-PKI-EMM-013
- REFERENCE: REQ-PKI-EMM-13
- REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the responderID field.
- RATIONALE: The product shall provide accurate certificates status as defined by the service provider chosen policies.
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses of the basic response type: UC1 and UC2.
@@ -1221,7 +1220,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
### 5.12.3 Certificate renewal
- REFERENCE: REQ-PKI-EMM-014
- REFERENCE: REQ-PKI-EMM-14
- REQUIREMENT: Requirement GEN-6.3.6-10 contained in ETSI EN 319 411-1 [\[7\]](#_ref_7) shall apply.
- NOTE: (TODO Remove note and provide the definition directly in the document) The term "sufficient" in the requirement means that the security is to be evaluated according to the current state of the art.
- RATIONALE: The product should never issue a certificate with foreseeable insufficient cryptographic security. The product should never issue a certificate for a key associated to any kind of security compromission.
@@ -1229,14 +1228,15 @@ To limit certificate forgery or misuse of certificate content, this section defi
### 5.12.3 Certificate re-key
- REFERENCE: REQ-PKI-EMM-015
- REFERENCE: REQ-PKI-EMM-15
- REQUIREMENT: In case of certificate re-key, any modified certified names or attributes shall be validated and updated registration information shall be recorded.
- RATIONALE: The product should never issue a certificate without having validated all its certified names and attributes at some point in time. The product should possess accurate registration information regarding certificates it re-keys.
- APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate re-key.
### 5.12.3 Certificate modification
- REFERENCE: REQ-5.7-01
- REFERENCE: REQ-PKI-EMM-16
- REQUIREMENT: In case of a request for certificate modification, any modified certified names or attributes shall be validated and updated registration information shall be recorded.
- NOTE: see ETSI 319 411-1 [i.3] clause 6.3.8 for the definition of certificate modification
- RATIONALE: The product should never issue a certificate without having validated all its certified names and attributes at some point in time. The product should possess accurate registration information regarding certificates it modifies.