Commit f128af7c authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Annex K rational

parent f52c1982
Loading
Loading
Loading
Loading
+8 −6
Original line number Diff line number Diff line
@@ -802,8 +802,8 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
### 5.3.3 SDBC - Cryptography

 - REFERENCE:  REQ-PKI-SBDC-03
  - REQUIREMENT: All cryptographic mechanisms shall be configured by default in conformity to Annex K requirements.
  - RATIONALE: XXX
  - REQUIREMENT: All cryptographic mechanisms shall be configured by default in conformity to the general state of the art as defined in Annex K.
  - RATIONALE: Cf. Annex K rational.
  - APPLICABILITY: All use cases.

### 5.3.4 SDBC - Certificates
@@ -885,7 +885,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

- REFERENCE: 	REQ-PKI-CON-02
  - REQUIREMENT: Where the private key is stored in a cryptographically protected way, the cryptographic mechanisms shall conform to the general state of the art as defined in Annex K.
  - RATIONALE: The use of recognized and validated cryptographic algorithms is mandatory for a PKI and thus a PKI product to ensure trust. Known weak or insufficiently validated algorithms are not allowed.
  - RATIONALE: Cf. Annex K rational.
  - APPLICABILITY: UC2, UC3, UC4 and UC5

- REFERENCE: 	REQ-PKI-CON-03
@@ -912,7 +912,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
  - APPLICABILITY: XXXX

- REFERENCE: 	REQ-PKI-CON-07
  - REQUIREMENT: The product shall implement cryptographic mechanisms as defined in Annex K and L to encrypt and decrypt, and sign and verify content.
  - REQUIREMENT: The cryptographic mechanisms used to sign and verify content shall conform to the general state of the art, as defined in Annex K.
  - RATIONALE: XXX
  - NOTE: If the product is intended for a specific environment with a defined set of agreed cryptographic mechanisms, the product has to be able to be used in accordance with those cryptographic requirements.
  - APPLICABILITY: XXXX
@@ -926,7 +926,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
### 5.6.2 Secure storage and communications

- REFERENCE: REQ-PKI-INT-06
  - REQUIREMENT: The product shall implement cryptographic mechanisms as defined in Annex K and L to encrypt and decrypt content.
  - REQUIREMENT:  The cryptographic mechanisms used to encrypt and decrypt content shall conform to the general state of the art, as defined in Annex K.
  - RATIONALE:
  - APPLICABILITY: All use cases where the product implements encryption mechanisms either for data storage or external communications.
  - NOTE:	If the product is intended for a specific environment with a defined set of agreed cryptographic mechanisms, the product has to be able to be used in accordance with those cryptographic requirements.
@@ -3641,9 +3641,11 @@ Note for Gisela, Clauses have been renumbered for consistency.

The product shall, by default, use State-of-the-Art cryptography algorithms listed in (CRY-SOTA), to be used for the supported security mechanism of the product where applicable.

- RATIONALE: Cryptographic mechanisms are the foundation of trust, integrity, and authenticity in digital systems. Using state-of-the-art cryptographic algorithms and protocols ensures protection against known vulnerabilities and cryptographic attacks. Failure to conform to CRY-SOTA risks compromising the integrity of signed content, enabling spoofing, tampering, or repudiation attacks, and undermining the overall security posture of the system.

> NOTE 1:	The use of security mechanism e.g. authentication, access control, secure communication, secure storage and secure update are described in the main text of this standard.

> NOTE 2:	Cryptographic algorithm primitives (in short, algorithms e.g. public- and private-key encryption algorithms, hash functions, authentication codes, digital signatures) are classified as CRY-SOTA if they are listed in the _ref_i.9  document and are suitable for the implementation of supported security mechanisms of the product.
> NOTE 2:	Cryptographic algorithm primitives (in short, algorithms e.g. public- and private-key encryption algorithms, hash functions, authentication codes, digital signatures) are classified as CRY-SOTA if they are listed in the  [\[i.9\]](#_ref_i.9) document and are suitable for the implementation of supported security mechanisms of the product.

> NOTE 3	Supporting evidence options that an algorithm, which is not included in CRY-SOTA, is applicable and suitable for the respective use case, are listed in the related assessment criteria ( K.1.2.1) clause.