- OBJECTIVE: Verify that the product requires the Administrator to specify the set of acceptable values for the fields and extensions identified in REQ-5.4-03.
- PREPARATION: Administrator access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no CRL may be issued until acceptables values for the issuer, issuerAltName and nextUpdate fields and extensions are set.
- VERDICT: SUCCESS if the verifications passes; else FAIL.
- EVIDENCE: The way CRLs were requested, and the responses from the product.
- REFERENCE: ACC_PKI_EMM_012
- OBJECTIVE: Verify the product implements and enforces an OCSP response profile for issued OCSP responses.
- PREPARATION: Ability to request an OCSP response as certificate status for a given certificate. Document the OCSP response profile implemented by the product.
- ACTIVITIES:
a) Request an OCSP response;
b) verify the OCSP response to match the constraints of the OCSP response profile.
- VERDICT: SUCCESS if all the verifications pass; else FAIL.
- EVIDENCE: The way the OCSP response was requested, and the response and OCSP response from the product.
- REFERENCE: ACC_PKI_EMM_013
- OBJECTIVE: Verify that the product requires the Administrator to specify the set of acceptable values for the responseType field.
- OBJECTIVE:
- Verify that the product requires the Administrator to specify the set of acceptable values for the responseType field.
- PREPARATION: Administrator access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responseType field are set.
- VERDICT: SUCCESS if all the verification pass; else FAIL.
- EVIDENCE: The way OCSP responses were requested, and the responses and OCSP responses from the product.
- REFERENCE: ACC_PKI_EMM_014
- OBJECTIVE: Verify that the product requires the Administrator to specify the set of acceptable values for the responderID field.
- PREPARATION: Administrator access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responderID field are set.
- VERDICT: SUCCESS if all the verification pass; else FAIL.
- EVIDENCE: The way OCSP responses were requested, and the responses and OCSP responses from the product.