@@ -1125,13 +1125,13 @@ To limit certificate forgery or misuse of certificate content, this section defi
- REFERENCE: REQ-PKI-EMM-01
- REQUIREMENT: The certificates issued by the certificate generation service shall comply with the X.509 standard ITU-T X.509 [\[3\]](#_ref_3) or with the IETF RFC 5280 standard or with the IEEE 1609.2 standard, and if known, to any extension or profile identified by the target systems' policy.
- RATIONALE: This extends what is mandated by ETSI EN 319 411-1 [\[7\]](#_ref_7) and takes into account the C-ITS PKI use case. Using normative formats ensures the interoperability of PKIs and enforces that certificate content contains only the normalised and necessary information.
- APPLICABILITY: TODO All use cases where the product has a certificate generation service.
- RATIONALE: This extends what is mandated by ETSI EN 319 411-1 [\[7\]](#_ref_7) and takes into account the C-ITS PKI use case. Using normative formats ensures the interoperability of PKIs and enforces that certificate content contains only normalised and necessary information.
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-EMM-02
- REQUIREMENT: The product shall implement a certificate profile and shall ensure that issued certificates are consistent with that profile.
- RATIONALE: To generate valid certificates, a product shall fallow a specific format and enforce mandatory content for the created certificates, corresponding to the implementation of a certificate policy.
- APPLICABILITY: TODO All use cases where the product has a certificate generation service.
- RATIONALE: Enforcing the implementation of a certificate policy ensures that authorized user can enforce interoperability of PKIs and that certificate content contains only normalised and necessary information to minimize attack surface.
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-EMM-03
- REQUIREMENT: The product shall enable authorized users to specify the set of acceptable values for the following fields and extensions:
@@ -1140,7 +1140,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
- the identifier of the certificate issuer;
- the length of time for which the certificate is valid.
- RATIONALE: Only valid certificates, as defined by authorized users in conformity with the PKI certificate policy, shall be generated by the product.
- APPLICABILITY: TODO All use cases where the product has a certificate generation service, issuing public-key certificates.
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-EMM-04
- REQUIREMENT: The product shall require authorized users to specify the set of acceptable values for the following fields and extensions:
@@ -1150,7 +1150,7 @@ To limit certificate forgery or misuse of certificate content, this section defi
- RATIONALE:
- APPLICABILITY: TODO All use cases where the product has a certificate generation service, issuing public-key certificates.
- APPLICABILITY: All use cases.
- REFERENCE: REQ-PKI-EMM-05
- REQUIREMENT: The product shall mark the following extensions as critical:
@@ -1515,7 +1515,6 @@ The assessment criteria for each security requirements are described in a struct
- List of stored configuration data.
- Documentation or logs showing the alignment of configuration data with PKI system requirements.