@@ -2657,7 +2657,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- FAIL: The product does not allow configuration of acceptable values for the required fields, or it issues CRLs before these values are fully defined.
- EVIDENCE: The way CRLs were requested, and the responses from the product.
- REFERENCE: ACC-PKI-EMM-011
- REFERENCE: ACC-PKI-EMM-11
- OBJECTIVE: Verify the product implements and enforces an OCSP response profile for issued OCSP responses.
- PREPARATION: Ability to request an OCSP response as certificate status for a given certificate. Document the OCSP response profile implemented by the product.
- ACTIVITIES:
@@ -2668,7 +2668,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- FAIL: Any OCSP response is issued that does not conform to the OCSP response profile or violates its defined constraints.
- EVIDENCE: The way the OCSP response was requested, and the response and OCSP response from the product.
- REFERENCE: ACC-PKI-EMM-012
- REFERENCE: ACC-PKI-EMM-12
- OBJECTIVE: Verify that the product requires the authorized users to specify the set of acceptable values for the responseType field.
- PREPARATION: Authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responseType field are set.
@@ -2677,7 +2677,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
- FAIL: The product allows issuance of OCSP responses without configured acceptable values for `responseType`.
- EVIDENCE: The way OCSP responses were requested, and the responses and OCSP responses from the product.
- REFERENCE: ACC-PKI-EMM-013
- REFERENCE: ACC-PKI-EMM-13
- OBJECTIVE: Verify that the product requires the authorized users to specify the set of acceptable values for the responderID field.
- PREPARATION: Authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
- ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responderID field are set.
@@ -2688,7 +2688,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
### 6.12.3 EMM - Certificate re-key
- REFERENCE: ACC-PKI-EMM-014
- REFERENCE: ACC-PKI-EMM-14
- OBJECTIVE:
- Verify that during certificate re-key operations, any modified certified names or attributes are validated and that updated registration information is properly recorded.
- PREPARATION:
@@ -2710,7 +2710,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
### 6.12.4 EMM - Certificate modification
- REFERENCE: ACC-PKI-EMM-015
- REFERENCE: ACC-PKI-EMM-15
- OBJECTIVE:
- Verify that during certificate modification operations, any modified certified names or attributes are validated and updated registration information is recorded.