Commit 8b2a7e96 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

New REQ-PKI-SBDC-03

parent a385d263
Loading
Loading
Loading
Loading
+9 −4
Original line number Diff line number Diff line
@@ -740,8 +740,6 @@ The product contains a number of assets that need privileged access to use. The

## 4.6 Use cases

The use cases considered are:

PKIs can take many forms and the present document does not aim to cover all possible services and their implementations but uses the use cases to assist in identifying the product requirements for these implementations. The uses cases considered are:
- **UC1**: Private PKI for non critical entities.
- **UC2**: Private PKI for critical entities.
@@ -749,7 +747,7 @@ PKIs can take many forms and the present document does not aim to cover all poss
- **UC4**: Open or Public basic PKI.
- **UC5**: Multi-authority PKI.

<mark>Each use case should clearly specify the users and privileges associated to each user. Details of these rights and privileges for each use case are given in Annex … In addition each use case should specify any constraints on the persistence of relationships, access or use of assets.</mark>
The following subsections present the use cases overviews, full details for use cases descriptions (functions, assets, interfarces, etc.) can be found in Annex U. 

### 4.6.1 Product for use in Private PKI for non critical sectors (UC1)

@@ -835,13 +833,20 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

TODO

### 5.3.1 SDBC - Monitoring
### 5.3.2 SDBC - Monitoring

 - REFERENCE:  REQ-PKI-SBDC-02
  - REQUIREMENT: The audit log signing event shall be performed by default once a day.
  - RATIONALE: The audit record intergrity ensure that all auditable events are traceable and misuse of the product functions can be traced.
  - APPLICABILITY: All use cases.

### 5.3.3 SDBC - Cryptography  

 - REFERENCE:  REQ-PKI-SBDC-03
  - REQUIREMENT: All cryptographic mechanisms shall be configured by default in conformity to Annex K requirements.
  - RATIONALE: XXX
  - APPLICABILITY: All use cases.

## 5.4 Secure updates

This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (c).