@@ -1124,6 +1124,11 @@ In this section we consider that certificates status availability and trust are
- RATIONALE: A PKI product requires multiple key pairs to provide essential services, including: support for different authorities (e.g., root CA, intermediate CAs, end-entities), use of various cryptographic mechanisms (e.g., separate key pairs for signing and encryption), facilitation of key rotation and lifecycle management (e.g., active and backup keys), etc.
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-AP-10
- REQUIREMENT: The product shall provide the capability for authorized users to delete keys.
- RATIONALE: Proper key management includes the capability for authorized users to delete key when necessary (as defined by the Certificate Policy).