Commit e442a537 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

ACC-PKI-EMM reqs renumbering

parent 43ee858b
Loading
Loading
Loading
Loading
+7 −8
Original line number Diff line number Diff line
@@ -2567,7 +2567,6 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
  - EVIDENCE:
    - The documentation of public-key certificate issuance circumstances;
    - The way issuances were requested, and the responses and issued certificates from the product.

- REFERENCE: ACC-PKI-EMM-06
  - OBJECTIVE:
    - Verify the product disallows the keyUsage extension to offer both digital signature and encryption or key agreement capabilities.
@@ -2585,7 +2584,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - The documentation of public-key certificate issuance circumstances;
    - The way issuances were requested, and the responses and issued certificates from the product.

- REFERENCE: ACC-PKI-EMM-08
- REFERENCE: ACC-PKI-EMM-06
  - OBJECTIVE:
    - Verify the product ensures a prospective certificate subject possesses the private key that corresponds to the public key in the certificate request before issuing a certificate, unless the private key never left the certificate issuance service.
  - PREPARATION: Document the circumstances in which the certificate generation service may issue a public-key certificate. Ability to request a certificate issuance.
@@ -2608,7 +2607,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on

### 6.12.2 EMM - Certificate status

- REFERENCE: ACC-PKI-EMM-09
- REFERENCE: ACC-PKI-EMM-07
  - OBJECTIVE: Verify the certificate revocation statuses to be either or both of CRLs as defined by and subject to the requirements of ITU-T X.509 [\[2\]](#_ref_2), or OCSP responses as defined by and subject to the requirements of RFC 6960 [\[i.3\]](#_ref_i.3).
  - PREPARATION: Document the circumstances in which the certificate generation service may issue a public-key certificate. Ability to request a certificate issuance. Ability to configure revocation aspects of the certificate profile if supported.
  - ACTIVITIES:
@@ -2622,7 +2621,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - The configuration attempts, or other evidence such configuration is not supported;
    - the way issuances were requested, and the responses from the product.

- REFERENCE: ACC-PKI-EMM-010
- REFERENCE: ACC-PKI-EMM-08
  - OBJECTIVE:
    - Verify the product implements and enforces a CRL profile for issued CRLs.
  - PREPARATION: Ability to request a CRL as certificate status for a given certificate. Document the CRL profile implemented by the product.
@@ -2632,14 +2631,14 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
  - VERDICT: SUCCESS if all the verifications pass; else FAIL.
  - EVIDENCE: The way the CRL was requested, and the response and CRL from the product.

- REFERENCE: ACC-PKI-EMM-011
- REFERENCE: ACC-PKI-EMM-09
  - OBJECTIVE: Verify that the product requires authorized users to specify the set of acceptable values for the fields and extensions identified in REQ-5.4-03.
  - PREPARATION: authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
  - ACTIVITIES: Verify that no CRL may be issued until acceptables values for the issuer, issuerAltName and nextUpdate fields and extensions are set.
  - VERDICT: SUCCESS if the verifications passes; else FAIL.
  - EVIDENCE: The way CRLs were requested, and the responses from the product.

- REFERENCE: ACC-PKI-EMM-012
- REFERENCE: ACC-PKI-EMM-010
  - OBJECTIVE: Verify the product implements and enforces an OCSP response profile for issued OCSP responses.
  - PREPARATION: Ability to request an OCSP response as certificate status for a given certificate. Document the OCSP response profile implemented by the product.
  - ACTIVITIES:
@@ -2648,14 +2647,14 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
  - VERDICT: SUCCESS if all the verifications pass; else FAIL.
  - EVIDENCE: The way the OCSP response was requested, and the response and OCSP response from the product.

- REFERENCE: ACC-PKI-EMM-013
- REFERENCE: ACC-PKI-EMM-011
  - OBJECTIVE: Verify that the product requires the authorized users to specify the set of acceptable values for the responseType field.
  - PREPARATION: Authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
  - ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responseType field are set.
  - VERDICT: SUCCESS if all the verification pass; else FAIL.
  - EVIDENCE: The way OCSP responses were requested, and the responses and OCSP responses from the product.

- REFERENCE: ACC-PKI-EMM-014
- REFERENCE: ACC-PKI-EMM-012
  - OBJECTIVE: Verify that the product requires the authorized users to specify the set of acceptable values for the responderID field.
  - PREPARATION: Authorized users access to not-installed or reinitialised product, or specifically its certificate status service and related configuration.
  - ACTIVITIES: Verify that no OCSP response may be issued until acceptable values for the responderID field are set.