@@ -835,7 +835,6 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- EXAMPLE: Options may include immediately on receipt, deferred to an agreed "maintenance" period.
- APPLICABILITY: All use cases.
## 5.5 Authentication and access control
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (d).
@@ -1034,6 +1033,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- APPLICABILITY: All use cases.
### 5.8.2 Secret management
- REFERENCE: REQ-PKI-DM-03
- REQUIREMENT: The product shall only create keys by means of a Secure Cryptographic Device (SCD) or remote Key Management System providing cryptographic mechanisms conform to the general state of the art as defined in Annex K.
- RATIONALE: To ensure trust the product software must rely on secure and valid key creation and management systems accessible only to authorised users provided by hardware security devices.
@@ -1113,7 +1113,6 @@ In this section we consider that certificates status availability and trust are
- APPLICABILITY: UC1, UC2 and UC3.
- NOTE: This is aligned with requirement CSS-6.3.10-09 contained in ETSI EN 319 411-1 [\[6\]](#_ref_5)
## 5.10 Impact minimisation
_Proposed ESR code: IM_
@@ -1133,7 +1132,6 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- RATIONALE: Only interfaces implementing functions provided by each use case are necessary.
- APPLICABILITY: All use cases.
## 5.12 Exploitation mitigation mechanisms
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (k).