Commit 7d88b050 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent 78ee2df6
Loading
Loading
Loading
Loading
+4 −10
Original line number Diff line number Diff line
@@ -1156,7 +1156,7 @@ To limit certificate forgery or misuse of certificate content, this section defi

- REFERENCE: REQ-PKI-EMM-02
  - REQUIREMENT: The product shall implement a certificate profile compliant to the base standard of REQ-PKI-EMM-01 (a or b) and appropriate to its scope/context  and shall ensure that issued certificates are consistent with that profile.
  - RATIONALE: EThe specification of a specific certificate profile (e.g. by reference to applicable standards such as IETF RFC 5280  [\[i.18\]](#_ref_i.18)  or ETSI TS 103 097  [\[i.19\]](#_ref_i.19) ) is in scope of a Certificate Policy and out of the scope of the present document. However, requiring the implementation of a certificate profile ensures that authorized users can ensure interoperability of PKIs and that certificate content contains only normalised and necessary information to minimize attack surface.
  - RATIONALE: The specification of a specific certificate profile (e.g. by reference to applicable standards such as IETF RFC 5280  [\[i.18\]](#_ref_i.18)  or ETSI TS 103 097  [\[i.19\]](#_ref_i.19) ) is in scope of a Certificate Policy and out of the scope of the present document. However, requiring the implementation of a certificate profile ensures that authorized users can ensure interoperability of PKIs and that certificate content contains only normalised and necessary information to minimize attack surface.
  - APPLICABILITY: All use cases.

- REFERENCE: REQ-PKI-EMM-03
@@ -4037,25 +4037,21 @@ Revocation management
    <td> F.OfficerRevocationApproval   </td>
    <td> STA01.Certificate status data <br> SYS03.Authorized user data   </td>
  </tr>

</table>
</div>

### U.4.4 UC4 - Operational Environment

Physical/Hardware
- POE.PartiallyControlled:	Partially controlled physical operational environment, none product users can access the product’s hardware it’s installed on.


- POE.SCD: The environment provides a Secure Cryptographic Device (often taking the form of an Hardware Security Module) to generate keys and provide signature support.
Logical Software
- SOE.PartiallyControlled	Partially controlled software operational environment product users can access the product’s interfaces and network data in transit.

- EC.Audit records secure storage:	External hardware and software use to store audit data.
- EC.Timesource:	A network server that synchronizes the clocks of devices within an IT infrastructure to ensure consistent and accurate timekeeping for security, logging, and operational purposes.
- EC.UserDirectory:	A directory server that centrally stores, organizes, and provides access to user, group, and resource information (e.g., authentication credentials, contact details) for networked systems and applications.
Connectivity
- COM.Public: Public communication

- COM.Local: Local communication

### U.4.5 UC4 - Distribution of Security Functions
@@ -4074,6 +4070,7 @@ In this UC the product should be able to defined user profile restriction on fun
- U.Operator	Performs operational tasks to ensure the availability and integrity of the product and data, e.g. execute system backups and recovery procedures to prevent data loss, monitor product health and performance, manage routine operational tasks, such as certificate issuance workflows.
- U.Officer (or Registration Authority Officer)	Manage certificate life-cycle operations, including approvals and revocations e.g. Configure profiles, policies, and security parameters, review and approve or reject certificate requests based on policy compliance, initiate and manage certificate revocation (e.g., due to compromise, expiration, or policy violations), verify the identity and authenticity of certificate applicants, ensure that certificate issuance and revocation processes align with organizational policies.
- U.Auditor	Authorized to monitor and review product operations logs to ensure compliance and security.

## U.5 UC5 - Product for use in Critical Multi-Authority PKI

### U.5.1 General description
@@ -4109,7 +4106,6 @@ Registration

Certificate generation
- F.SCD_BasedKeyPairGen:	Request the generation of the public-private key pair to an external SCD.

- F.SubjectCertSignCreation:	Creates and signs subject certificates based on the identity and other attributes verified by the registration service
- F.OfficerCertGenApproval:	Privileged users to approve and execute this issuance, when certificates are issued.
- F.PseudonymCertIssuance:	Issuance of pseudonym certificates derived from long-term certificates Those certificates shall not include user identification data.
@@ -4209,11 +4205,11 @@ Revocation management
</table>

</div>

### U.5.4 UC5 - Operational Environment

Physical/Hardware
- POE.FullyControlled:	Fully controlled physical operational environment, where only authorized users have access to the product interfaces.

- POE.SCD: The environment provides a Secure Cryptographic Device (often taking the form of an Hardware Security Module) to generate keys and provide signature support.


@@ -4223,13 +4219,11 @@ Logical Software

External component
- EC.Timesource:	A network server that synchronizes the clocks of devices within an IT infrastructure to ensure consistent and accurate timekeeping for security, logging, and operational purposes.

- EC.UserDirectory:	A directory server that centrally stores, organizes, and provides access to user, group, and resource information (e.g., authentication credentials, contact details) for networked systems and applications.


Connectivity
- COM.Public: Public communication

- COM.Local: Local communication

### U.5.5 UC5 - Distribution of Security Functions