Commit e715e419 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

ACC-PKI-INT-07 update

parent 32765b92
Loading
Loading
Loading
Loading
+3 −2
Original line number Diff line number Diff line
@@ -997,7 +997,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- REFERENCE: REQ-PKI-INT-06
  - REQUIREMENT: The product shall create certificate signature only by means of a Secure Cryptographic Device (SCD).
  - RATIONALE: To ensure trust the product software must rely on secure and valid key creation and management systems accessible only to authorised users provided by hardware security devices.
  - APPLICABILITY: UC2, UC3, UC4 and UC5
  - APPLICABILITY: UC3, UC4 and UC5

- REFERENCE: REQ-PKI-INT-07
  - REQUIREMENT: The cryptographic mechanisms used to create certificate signatures shall be as stated in Annex K.
@@ -1967,7 +1967,7 @@ The validity of the cryptographic mechanisms used to encure those funtions is co

- REFERENCE: ACC-PKI-INT-04
  - OBJECTIVE:
    - Verify that the product ensures the integrity of audit logs using appropriate protection mechanisms whithout Annex Conformant cryptographic mechanisms.
    - Verify that the product ensures the integrity of audit logs using appropriate protection mechanisms without Annex Conformant cryptographic mechanisms.
  - PREPARATION:
    - Obtain logging architecture documentation.
    - Obtain integrity protection configuration.
@@ -2038,6 +2038,7 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
  - ACTIVITIES:
    - Generate CRLs.
    - Observe signing operations.
    - Verify that SCD logs identify the signature creation request and generation. 
    - Verify that signing keys remain within the SCD.
    - Attempt CRL generation without the SCD.
  - VERDICT: