@@ -983,14 +983,18 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- REFERENCE: REQ-PKI-DM-01
- REQUIREMENT: The product shall only maintain configuration data sufficient to connect to other elements of the PKI system that the product serves.
- RATIONALE: Unecessary elements adds unecessary complexity and potential attack surface.
- RATIONALE: Unnecessary network configuration elements add complexity and increase the potential attack surface.
- APPLICABILITY: UC1, UC2, UC3, and UC5
- REFERENCE: REQ-PKI-DM-01
- REQUIREMENT: The product shall only maintain configuration data sufficient to provide PKC management functions.
- RATIONALE: Unnecessary PKC management function configurations (as defined per use case in Annex U) introduce unnecessary complexity and avoidable risks.
- APPLICABILITY: UC1, UC2, UC3, and UC5
- REFERENCE: REQ-PKI-DM-02
- REQUIREMENT: The product shall only maintain and process user data necessary for certificate management (e.g. certificate requests, updates)
- RATIONALE: XXX
- NOTE:XXX
- APPLICABILITY: XXXX
- REQUIREMENT: The product shall only maintain and process user data necessary for certificate management (e.g. certificate requests, updates).
- RATIONALE: For each use case, only user data necessary for the certificate management functions identified in Annex U are required.