- RATIONALE: The same public key may not be used for signature verification, and encryption or key agreement. Only valid certifcates as defined by the PKI service provider policies shall be generated by the product.
@@ -1201,7 +1201,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
- APPLICABILITY: Where the product has a certificate status service, issuing CRLs.
- REFERENCE: REQ-PKI-EMM-10
- REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the following CRL fields and extensions:
- REQUIREMENT: The product shall enable authorized users to specify the set of acceptable values for the following CRL fields and extensions:
- issuer;
- issuerAltName;
- nextUpdate.
@@ -1215,12 +1215,12 @@ To limit certificate forgery or misuse of certificate content, this section defi
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses.
- REFERENCE: REQ-PKI-EMM-012
- REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the responseType field.
- REQUIREMENT: The product shall enable authorized users to specify the set of acceptable values for the responseType field.
- RATIONALE: The product shall provide accurate certificates statusas defined by the service provider chosen policies.
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses, not restricted to the basic response type: UC1 and UC2.
- REFERENCE: REQ-PKI-EMM-13
- REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the responderID field.
- REQUIREMENT: The product shall enable authorized users to specify the set of acceptable values for the responderID field.
- RATIONALE: The product shall provide accurate certificates status as defined by the service provider chosen policies.
- APPLICABILITY: Where the product has a certificate status service, issuing OCSP responses of the basic response type: UC1 and UC2.
- NOTE: An OCSP responder is required to be capable to emit OCSP responses of the basic type by RFC 6960 [\[i.3\]](#_ref_i.3).
@@ -1587,7 +1587,7 @@ The assessment criteria for each security requirements are described in a struct
- Prepare test scenarios for different update installation options (e.g., immediate, deferred).
- ACTIVITIES:
- Configure the product to install updates immediately upon receipt and verify the behavior.
- Configure the product to defer updates to a specified maintenance period and verify the behavior.
- Configure the product to defer updates to a specified maintenance to specify the set of acceptable values for the and verify the behavior.
- Attempt to trigger an update under each configuration and confirm it follows the configured timing.
- Verify that the administrator has sufficient control over the update timing.
- VERDICT:
@@ -2514,7 +2514,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- the way issuances were requested, and the responses and issued certificates from the product.
- REFERENCE: ACC-PKI-EMM-04
- OBJECTIVE: Verify that the product requires the authorized user to specify the set of acceptable values for the fields and extensions: keyUsage, basicConstraints, CertificatePolicies.
- OBJECTIVE: Verify that the product enables the authorized user to specify the set of acceptable values for the fields and extensions: keyUsage, basicConstraints, CertificatePolicies.
- PREPARATION:
- Certificate generation service documentation.
- Authorized user access to certificate generation service and related configuration.
@@ -2624,7 +2624,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- EVIDENCE: The way the CRL was requested, and the response and CRL from the product.
- REFERENCE: ACC-PKI-EMM-10
- OBJECTIVE: Verify that the product requires authorized users to specify the set of acceptable values for the fields and extensions: `issuer`, `issuerAltName`,
- OBJECTIVE: Verify that the product enables authorized users to specify the set of acceptable values for the fields and extensions: `issuer`, `issuerAltName`,
`nextUpdate`.
- PREPARATION: authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES:
@@ -2647,7 +2647,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- EVIDENCE: The way the OCSP response was requested, and the response and OCSP response from the product.
- REFERENCE: ACC-PKI-EMM-12
- OBJECTIVE: Verify that the product requires the authorized users to specify the set of acceptable values for the responseType field.
- OBJECTIVE: Verify that the product enables the authorized users to specify the set of acceptable values for the responseType field.
- PREPARATION: Authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responseType field are set.
- VERDICT:
@@ -2656,7 +2656,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- EVIDENCE: The way OCSP responses were requested, and the responses and OCSP responses from the product.
- REFERENCE: ACC-PKI-EMM-13
- OBJECTIVE: Verify that the product requires the authorized users to specify the set of acceptable values for the responderID field.
- OBJECTIVE: Verify that the product enables the authorized users to specify the set of acceptable values for the responderID field.
- PREPARATION: Authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responderID field are set.