@@ -976,8 +976,6 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
## 5.7 Integrity
_Proposed ESR code: INT_
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (f).
### 5.7.1 Monitoring
@@ -1087,12 +1085,12 @@ In this section we consider that certificates status availability and trust are
### 5.9.2 Certificate status services
- REFERENCE: REQ-PKI-AP-002
- REQUIREMENT: Requirements CSS-6.3.10-03, CSS-6.3.10-04 and CSS-6.3.10-05 contained in ETSI EN 319 411-1 [\[7\]](#_ref_7) shall apply.
- RATIONALE: The product shall provide accurate and integrity protected certificates statues either using the standardised CRL format ensuring integrity of revocation list or protected OCSP services as defined by RFC 6960 [\[i.3\]](#_ref_i.3). This covers threats T_REV01 to T_REV03 and T_STA01 to T_STA02.
- RATIONALE: The product shall provide accurate and integrity protected certificates statues either using the standardised CRL format ensuring integrity of revocation list or protected OCSP services as defined by RFC 6960 [\[i.3\]](#_ref_i.3).
- APPLICABILITY: UC1, UC2 and UC3.
- REFERENCE: REQ-PKI-AP-003
- REQUIREMENT: If a product supports multiple methods to provide revocation status, the information provided by all services shall be consistent over time taking into account different delays in updating the status information for all the methods.
- RATIONALE: The product shall provide accurate and integrity protected certificates statues either using the standardised CRL format ensuring integrity of revocation list or protected OCSP services as defined by RFC 6960 [\[i.3\]](#_ref_i.3). This covers threats T_REV01 to T_REV03 and T_STA01 to T_STA02.
- RATIONALE: The product shall provide accurate and integrity protected certificates statues either using the standardised CRL format ensuring integrity of revocation list or protected OCSP services as defined by RFC 6960 [\[i.3\]](#_ref_i.3).
- APPLICABILITY: UC1, UC2 and UC3.
- NOTE: This is aligned with requirement CSS-6.3.10-09 contained in ETSI EN 319 411-1 [\[7\]](#_ref_7)
@@ -1282,8 +1280,6 @@ These requirements are about the collection and handling of "auditable events",
## 5.14 Data removal and transparency
_Proposed ESR code: DRT_
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (m).
### 5.14.1 Secret management
@@ -1292,7 +1288,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- REQUIREMENT: Public keys stored within the product, but not within a secure cryptographic device, shall be protected against undetected modification. If verification fails, the product shall not:
- release the accessed public key to the caller; or
- use the accessed public key.
- RATIONALE: Unauthorized modifications of public keys stored by the product should not go undetected. Public keys modified without authorization should not be considered safe for use and not be disseminated throughout or outside the product. This requirement covers key tampering and disclosure threats: T_GEN01 to T_GEN08, T.Stored_Certificates_Tampering.
- RATIONALE: Unauthorized modifications of public keys stored by the product should not go undetected. Public keys modified without authorization should not be considered safe for use and not be disseminated throughout or outside the product.