@@ -1016,13 +1016,12 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- RATIONALE: The use of recognized and validated cryptographic algorithms is mandatory for a PKI and thus a PKI product to ensure trust. Known weak or insufficiently validated algorithms are not allowed.
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-AP-03
- REFERENCE: REQ-PKI-INT-10
- REQUIREMENT - [CONDITIONAL]: If Certificate Revocation Lists (CRLs) concerning end users certificates including any variants (e.g. Delta CRLs) are used, the CRL shall be signed using a valid certificate.
- NOTE: This Requirement correspond to CSS-6.3.9-08 contained in ETSI EN 319 411-1 [\[i.10\]](#_ref_i.10)
- RATIONALE: If the CRL is not signed by the CA or a TSP-appointed entity, it may be usurped to mislead end-users regarding a certificate's status.
- APPLICABILITY: Where the product has a certificate status service, issuing CRLs.
## 5.8 Data minimisation
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (g).