Commit a9fa77c2 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent c25c3023
Loading
Loading
Loading
Loading
+6 −24
Original line number Diff line number Diff line
@@ -1100,7 +1100,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
To limit certificate forgery or misuse of certificate content, this section defines requirements for the PKI to enforce the use of standardized certificate formats and recognized cryptographic signature mechanisms.

- REFERENCE: REQ-PKI-EMM-01
  - REQUIREMENT: The certificates issued by the certificate generation service shall comply with the X.509 standard ITU-T X.509 [\[2\]](#_ref_2) or with the IETF RFC 5280 standard or with the IEEE 1609.2 standard, and if known, to any extension or profile identified by the target systems' policy.
  - REQUIREMENT: The certificates format issued by the certificate generation service shall comply with the X.509 standard ITU-T X.509 [\[2\]](#_ref_2) or with the IETF RFC 5280 standard or with the IEEE 1609.2 standard, and if known, to any extension or profile identified by the target systems' policy.
  - RATIONALE: This extends what is mandated by ETSI EN 319 411-1  [\[6\]](#_ref_5) and takes into account the C-ITS PKI use case. Using normative formats ensures the interoperability of PKIs and enforces that certificate content contains only normalised and necessary information.
  - APPLICABILITY:  All use cases.

@@ -1163,15 +1163,15 @@ To limit certificate forgery or misuse of certificate content, this section defi
- REFERENCE: REQ-PKI-EMM-09
  - REQUIREMENT: The product shall implement a CRL profile and shall ensure that issued CRls are consistent with that profile.
  - RATIONALE:  The product shall provide accurate and integrity protected certificates statues using the standardised CRL format ensuring integrity of revocation list and conformity to the product service provider chosen policies.
  - APPLICABILITY: Where the product has a certificate status service, issuing CRLs: UC1 and UC2.
  - APPLICABILITY: Where the product has a certificate status service, issuing CRLs.

- REFERENCE: REQ-PKI-EMM-10
  - REQUIREMENT: TODO(Specify that it is for CRL?) The product shall require authorized users to specify the set of acceptable values for the following fields and extensions:
  - REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the following CRL fields and extensions:
    - issuer;
    - issuerAltName;
    - nextUpdate.
  - RATIONALE: The product shall provide accurate and integrity protected certificates statues using the standardised CRL format ensuring integrity of revocation list and conformity to the product service provider chosen policies.
  - APPLICABILITY: Where the product has a certificate status service, issuing CRLs: UC1 and UC2.
  - APPLICABILITY: Where the product has a certificate status service, issuing CRLs.
  - NOTE: The issuerAltName may be absent from the profile if issued certificates do not use it.

- REFERENCE: REQ-PKI-EMM-11
@@ -1194,7 +1194,7 @@ To limit certificate forgery or misuse of certificate content, this section defi

- REFERENCE: REQ-PKI-EMM-014
  - REQUIREMENT: Requirement GEN-6.3.6-10 contained in ETSI EN 319 411-1  [\[6\]](#_ref_5) shall apply.
  - NOTE: (TODO Remove note and provide the definition directly in the document) The term "sufficient" in the requirement means that the security is to be evaluated according to the current state of the art.
  - NOTE: 
  - RATIONALE: The product should never issue a certificate with foreseeable insufficient cryptographic security. The product should never issue a certificate for a key associated to any kind of security compromission.
  - APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate renewal.

@@ -1210,7 +1210,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
  - REFERENCE: REQ-PKI-EMM-16

    - REQUIREMENT: In case of a request for certificate modification, any modified certified names or attributes shall be validated and updated registration information shall be recorded.
    - NOTE: see ETSI 319 411-1 [i.3] clause 6.3.8 for the definition of certificate modification
    - NOTE: see ETSI 319 411-1 [i.3] clause 6.3.8 for the definition of certificate modification.
    - RATIONALE: The product should never issue a certificate without having validated all its certified names and attributes at some point in time. The product should possess accurate registration information regarding certificates it modifies.
    - APPLICABILITY: All use cases where the product has a certificate generation service, issuing public-key certificates and supporting certificate modification.

@@ -3991,7 +3991,6 @@ updatable by a recommended algorithm in the documentation.
- The verdict PASS shall be assigned if respective evidence has been provided,
- The verdict FAIL shall be assigned otherwise.


# Annex U: Use case description

## U.1 UC1 - Product for use in Private PKI for non critical sectors
@@ -4002,8 +4001,6 @@ Additionally, users of these PKI solutions often prioritize flexibility and ease

TO DO Include in the description an overview of what is presented in the next subsections (env., archi, users.).

TO DO - Include UC1 functional figure

**Figure U.1.2: UC1 functional architecture**

![Figure U.1.2: UC1 functional architecture](media/Figures/UC_Architecture/UC1.png)
@@ -4039,8 +4036,6 @@ Revocation management

### U.1.3.2 UC1 - Assets

TODO Giulio - Provide the mapping table functions - assests.


**Table: Mapping between Functions and Assets for UC1**

@@ -4594,14 +4589,8 @@ TODO

</div>






### U.3.4 UC3 - Operational Environment


Physical/Hardware
- POE.FullyControlled
- POE.SCD
@@ -4640,9 +4629,6 @@ In this UC the product should be able to defined user profile restriction on fun
- U.Officer (or Registration Authority Officer)
- U.Auditor




## U.4 UC4 - Product for use in Critical Public basic PKI

### U.4.1 General description (?)
@@ -4683,10 +4669,6 @@ Revocation management

### U.4.3.1 UC4 - Assets

TODO





**Table: Mapping between Functions and Assets for UC4**