Commit e884f95a authored by Sammy Haddad's avatar Sammy Haddad
Browse files

REQ-PKI-EMM-03 rational update

parent 12a57c7c
Loading
Loading
Loading
Loading
+6 −7
Original line number Diff line number Diff line
@@ -1125,13 +1125,13 @@ To limit certificate forgery or misuse of certificate content, this section defi

- REFERENCE: REQ-PKI-EMM-01
  - REQUIREMENT: The certificates issued by the certificate generation service shall comply with the X.509 standard ITU-T X.509 [\[3\]](#_ref_3) or with the IETF RFC 5280 standard or with the IEEE 1609.2 standard, and if known, to any extension or profile identified by the target systems' policy.
  - RATIONALE: This extends what is mandated by ETSI EN 319 411-1  [\[7\]](#_ref_7) and takes into account the C-ITS PKI use case. Using normative formats ensures the interoperability of PKIs and enforces that certificate content contains only the normalised and necessary information.
  - APPLICABILITY:  TODO All use cases where the product has a certificate generation service.
  - RATIONALE: This extends what is mandated by ETSI EN 319 411-1  [\[7\]](#_ref_7) and takes into account the C-ITS PKI use case. Using normative formats ensures the interoperability of PKIs and enforces that certificate content contains only normalised and necessary information.
  - APPLICABILITY:  All use cases. 

- REFERENCE: REQ-PKI-EMM-02
  - REQUIREMENT: The product shall implement a certificate profile and shall ensure that issued certificates are consistent with that profile.
  - RATIONALE: To generate valid certificates, a product shall fallow a specific format and enforce mandatory content for the created certificates, corresponding to the implementation of a certificate policy.
  - APPLICABILITY: TODO All use cases where the product has a certificate generation service.
  - RATIONALE: Enforcing the implementation of a certificate policy ensures that authorized user can enforce interoperability of PKIs and that certificate content contains only normalised and necessary information to minimize attack surface.
  - APPLICABILITY: All use cases.

- REFERENCE: REQ-PKI-EMM-03
  - REQUIREMENT: The product shall enable authorized users to specify the set of acceptable values for the following fields and extensions:
@@ -1140,7 +1140,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
    - the identifier of the certificate issuer;
    - the length of time for which the certificate is valid.
  - RATIONALE: Only valid certificates, as defined by authorized users in conformity with the PKI certificate policy, shall be generated by the product.
  - APPLICABILITY: TODO All use cases where the product has a certificate generation service, issuing public-key certificates.
  - APPLICABILITY: All use cases.

- REFERENCE: REQ-PKI-EMM-04
  - REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the following fields and extensions:
@@ -1150,7 +1150,7 @@ To limit certificate forgery or misuse of certificate content, this section defi

  - RATIONALE:

  - APPLICABILITY: TODO All use cases where the product has a certificate generation service, issuing public-key certificates.
  - APPLICABILITY: All use cases.

- REFERENCE: REQ-PKI-EMM-05
  - REQUIREMENT: The product shall mark the following extensions as critical:
@@ -1515,7 +1515,6 @@ The assessment criteria for each security requirements are described in a struct
  - List of stored configuration data.
  - Documentation or logs showing the alignment of configuration data with PKI system requirements.


- REFERENCE: REQ-PKI-DM-02

- OBJECTIVE: