RFC 3647 - Internet X.509 Public Key Infrastructure Certific(7)

时间:2006-10-21 来源: 作者: 点击:
9.6.3,9.9 ------------------------------------------------------ 2.1.4RelyingPartyObligations4.5,4.5.2,4.9.6, 5.,6.,9.6.4,9.9 ------------------------------------------------------ 2.1.5RepositoryObl
  
                                         9.6.3, 9.9
   ------------------------------------------------------
   2.1.4 Relying Party Obligations     4.5, 4.5.2, 4.9.6,
                                       5., 6., 9.6.4, 9.9
   ------------------------------------------------------
   2.1.5 Repository Obligations        2., 4.4.2, 4.4.3,
                                       4.6.6, 4.6.7,
                                       4.7.6, 4.7.7,
                                       4.8.6, 4.8.7
   ------------------------------------------------------
   2.2 Liability                       9.6, 9.7, 9.8, 9.9
   ------------------------------------------------------
   2.2.1 CA Liability                  9.6.1, 9.7., 9.8,
                                       9.9
   ------------------------------------------------------
   2.2.2 RA Liability                  9.6.2, 9.7, 9.8, 9.9
   ------------------------------------------------------
   2.3 Financial Responsibility                9.2
   ------------------------------------------------------
   2.3.1 Indemnification by Relying
         Parties                               9.9
   ------------------------------------------------------
   2.3.2 Fiduciary Relationships               9.7
   ------------------------------------------------------
   2.4 Interpretation and Enforcement          9.16
   ------------------------------------------------------
   2.4.1 Governing Law                         9.14, 9.15
   ------------------------------------------------------
   2.4.2 Severability, Survival,
         Merger, Notice                9.10.3, 9.11,
                                       9.16.1,9.16.3
   ------------------------------------------------------
   2.4.3 Dispute Resolution
         Procedures                    9.13, 9.16.4
   ------------------------------------------------------
   2.5 Fees                                    9.1
   ------------------------------------------------------
   2.5.1 Certificate Issuance
         or Renewal Fees                       9.1.1
   ------------------------------------------------------
   2.5.2 Certificate Access Fees               9.1.2

   ------------------------------------------------------
   2.5.3 Revocation or Status
         Information Access Fees               9.1.3
   ------------------------------------------------------
   2.5.4 Fees for Other Services Such
         as Policy Information                 9.1.4
   ------------------------------------------------------
   2.5.5 Refund Policy                         9.1.5
   ------------------------------------------------------
   2.6 Publication and Repository              2.
   ------------------------------------------------------
   2.6.1 Publication of CA
         Information                    2.2, 4.4.2,
                                        4.4.3, 4.6.6,
                                        4.6.7, 4.7.6,
                                        4.7.7, 4.8.6,
                                        4.8.7
   ------------------------------------------------------
   2.6.2 Frequency of Publication              2.3
   ------------------------------------------------------
   2.6.3 Access Controls                       2.4
   ------------------------------------------------------
   2.6.4 Repositories                          2.1
   ------------------------------------------------------
   2.7 Compliance Audit                        8.
   ------------------------------------------------------
   2.7.1 Frequency of Entity Compliance
         Audit                                 8.1
   ------------------------------------------------------
   2.7.2 Identity/Qualifications of
         Auditor                               8.2
   ------------------------------------------------------
   2.7.3 Auditor’s Relationship to Audited
         Party                                 8.3
   ------------------------------------------------------
   2.7.4 Topics Covered by Audit               8.4
   ------------------------------------------------------
   2.7.5 Actions Taken as a Result of
         Deficiency                            8.5
   ------------------------------------------------------
   2.7.6 Communications of Results             8.6
   ------------------------------------------------------
   2.8 Confidentiality                         9.3, 9.4
   ------------------------------------------------------
   2.8.1 Types of Information to be
         Kept Confidential              9.3.1, 9.4.2

   ------------------------------------------------------
   2.8.2 Types of Information Not
         Considered Confidential        9.3.2, 9.4.3
   ------------------------------------------------------
   2.8.3 Disclosure of Certificate
         Revocation/Suspension
         Information                    9.3.1, 9.3.2,
                                        9.3.3, 9.4.2,
                                        9.4.3, 9.4.4
   ------------------------------------------------------
   2.8.4 Release to Law Enforcement
         Officials                      9.3.3, 9.4.6
   ------------------------------------------------------
   2.8.5 Release as Part of Civil
   Discovery                            9.3.3, 9.4.6
   ------------------------------------------------------
   2.8.6 Disclosure Upon Owner’s
         Request                        9.3.3, 9.4.7
   ------------------------------------------------------
   2.8.7 Other Information Release
         Circumstances                  9.3.3, 9.4.7
   ------------------------------------------------------
   2.9 Intellectual Property Rights            9.5
   ------------------------------------------------------
   3. Identification and Authentication        3.
   ------------------------------------------------------
   3.1 Initial Registration                    3.1, 3.2
   ------------------------------------------------------
   3.1.1 Type of Names                         3.1.1
   ------------------------------------------------------
   3.1.2 Need for Names to be
         Meaningful                     3.1.2, 3.1.3
   ------------------------------------------------------
   3.1.3 Rules for Interpreting
         Various Name Forms                    3.1.4
   ------------------------------------------------------
   3.1.4 Uniqueness of Names                   3.1.5
   ------------------------------------------------------
   3.1.5 Name Claim Dispute
         Resolution Procedure                  3.1.6
   ------------------------------------------------------
   3.1.6 Recognition, Authentication,
         and Role of Trademarks                3.1.6
   ------------------------------------------------------
   3.1.7 Method to Prove Possession
         of Private Key                        3.2.1

   ------------------------------------------------------
   3.1.8 Authentication of
         Organization Identity                 3.2.2
   ------------------------------------------------------
   3.1.9 Authentication of
         Individual Identity                   3.2.3
   ------------------------------------------------------
   3.2 Routine Rekey                    3.3.1, 4.6, 4.7
   ------------------------------------------------------
   3.3 Rekey After Revocation                  3.3.2
   ------------------------------------------------------
   3.4 Revocation Request                      3.4
   ------------------------------------------------------
   4.  Operational Requirements                4., 5.
   ------------------------------------------------------
   4.1 Certificate Application          4.1, 4.2, 4.6,
                                        4.7
   ------------------------------------------------------
   4.2 Certificate Issuance             4.2, 4.3, 4.4.3,
                                        4.6, 4.7, 4.8.4,
                                        4.8.6, 4.8.7
   ------------------------------------------------------
   4.3 Certificate Acceptance           4.3.2, 4.4, 4.6,
                                        4.7, 4.8.4-4.8.7
   ------------------------------------------------------
   4.4 Certificate Suspension
       and Revocation                          4.8, 4.9
   ------------------------------------------------------
   4.4.1 Circumstances for Revocation   4.8.1, 4.9.1
   ------------------------------------------------------
   4.4.2 Who Can Request Revocation     4.8.2, 4.9.2
   ------------------------------------------------------
   4.4.3 Procedure for Revocation
         Request                        4.8.3-4.8.7,
                                        4.9.3
   ------------------------------------------------------
   4.4.4 Revocation Request
         Grace Period                          4.9.4
   ------------------------------------------------------
   4.4.5 Circumstances for Suspension          4.9.13
   ------------------------------------------------------
   4.4.6 Who Can Request Suspension            4.9.14
   ------------------------------------------------------
   4.4.7 Procedure for Suspension
         Request                               4.9.15
   ------------------------------------------------------
   4.4.8 Limits on Suspension Period           4.9.16

   ------------------------------------------------------
   4.4.9 CRL Issuance Frequency
         (If Applicable)                  4.9.7, 4.9.8,
                                          4.10
   ------------------------------------------------------
   4.4.10 CRL Checking Requirements       4.9.6, 4.10
   ------------------------------------------------------
   4.4.11 On-Line Revocation/
          Status Checking
          Availability                    4.9.9, 4.10
   ------------------------------------------------------
   4.4.12 On-Line Revocation
          Checking Requirements           4.9.6, 4.9.10,
                                          4.10
   ------------------------------------------------------
   4.4.13 Other Forms
          of Revocation
          Advertisements                  4.9.11, 4.10
   ------------------------------------------------------
   4.4.14 Checking Requirements
          for Other Forms of
          Revocation
          Advertisements                  4.9.6, 4.9.11,
                                          4.10
   ------------------------------------------------------
   4.4.15 Special Requirements re
          Key Compromise                        4.9.12
   ------------------------------------------------------
   4.5 Security Audit Procedures                5.4
   ------------------------------------------------------
   4.5.1 Types of Events Recorded               5.4.1
   ------------------------------------------------------
   4.5.2 Frequency of Processing Log            5.4.2
   ------------------------------------------------------
   4.5.3 Retention Period for Audit
         Log                                    5.4.3
   ------------------------------------------------------
   4.5.4 Protection of Audit Log                5.4.4
   ------------------------------------------------------
   4.5.5 Audit Log Backup Procedures            5.4.5
   ------------------------------------------------------
   4.5.6 Audit Collection System
         (Internal vs. External)                5.4.6
   ------------------------------------------------------
   4.5.7 Notification to Event-Causing
         Subject                                5.4.7
   ------------------------------------------------------
   4.5.8 Vulnerability Assessments              5.4.8

   ------------------------------------------------------
   4.6 Records Archival                         5.5
   ------------------------------------------------------
   4.6.1 Types of Records Archived              5.5.1
   ------------------------------------------------------
   4.6.2 Retention Period for Archive           5.5.2
   ------------------------------------------------------
   4.6.3 Protection of Archive                  5.5.3
   ------------------------------------------------------
   4.6.4 Archive Backup Procedures              5.5.4
   ------------------------------------------------------
   4.6.5 Requirements for
         Time-Stamping of Records               5.5.5
   ------------------------------------------------------
   4.6.6 Archive Collection System
         (Internal or External)                 5.5.6
   ------------------------------------------------------
   4.6.6 Procedures to Obtain and
         Verify Archive Information             5.5.7
   ------------------------------------------------------
   4.7 Key Changeover                           5.6
   ------------------------------------------------------
   4.8 Compromise and Disaster
       Recovery                           5.7, 5.7.1
   ------------------------------------------------------
   4.8.1 Computing Resources, Software,
         and/or Data Are Corrupted              5.7.2
   ------------------------------------------------------
   4.8.2 Entity Public
         Key is Revoked                   4.9.7, 4.9.9,
                                          4.9.11
   ------------------------------------------------------
   4.8.3 Entity Key is Compromised             5.7.3
   ------------------------------------------------------
   4.8.4 Secure Facility After a Natural
         or Other Type of Disaster             5.7.4
   ------------------------------------------------------
   4.9 CA Termination                          5.8
   ------------------------------------------------------
   5. Physical, Procedural, and
      Personnel Security Controls              5.
   ------------------------------------------------------
   5.1 Physical Controls                       5.1
   ------------------------------------------------------
   5.1.1 Site Location and Construction        5.1.1
   ------------------------------------------------------
   5.1.2 Physical Access                       5.1.2

   ------------------------------------------------------
   5.1.3 Power and Air Conditioning            5.1.3
   ------------------------------------------------------

   5.1.4 Water Exposures                       5.1.4
   ------------------------------------------------------
   5.1.5 Fire Prevention and Protection        5.1.5
   ------------------------------------------------------
   5.1.6 Media Storage                         5.1.6
   ------------------------------------------------------
   5.1.7 Waste Disposal                        5.1.7
   ------------------------------------------------------
   5.1.8 Off-Site Backup                       5.1.8
   ------------------------------------------------------
   5.2 Procedural Controls                     5.2
   ------------------------------------------------------
   5.2.1 Trusted Roles                    5.2.1, 5.2.4
   ------------------------------------------------------
   5.2.2 Number of Persons
         Required per Task                5.2.2, 5.2.4
   ------------------------------------------------------
   5.2.3 Identification and
         Authentication for Each Role          5.2.3
   ------------------------------------------------------
   5.3 Personnel Controls                      5.3
   ------------------------------------------------------
   5.3.1 Background, Qualifications,
         Experience, and Clearance
         Requirements                          5.3.1
   ------------------------------------------------------
   5.3.2 Background Check Procedures           5.3.2
   ------------------------------------------------------
   5.3.3 Training Requirements                 5.3.3
   ------------------------------------------------------
   5.3.4 Retraining Frequency
         and Requirements                      5.3.4
   ------------------------------------------------------
   5.3.5 Job Rotation Frequency
         and Sequence                          5.3.5
   ------------------------------------------------------
   5.3.6 Sanctions for
         Unauthorized Actions                  5.3.6
   ------------------------------------------------------
   5.3.7 Contracting Personnel
         Requirements                          5.3.7
   ------------------------------------------------------
   5.3.8 Documentation Supplied to
         Personnel                             5.3.8

   ------------------------------------------------------
   6. Technical Security Controls              6.
   ------------------------------------------------------
   6.1 Key Pair Generation and
       Installation                            6.1
   ------------------------------------------------------
   6.1.1 Key Pair Generation                   6.1.1
   ------------------------------------------------------
   6.1.2 Private Key Delivery to Entity        6.1.2
   ------------------------------------------------------
   6.1.3 Public Key Delivery to
         Certificate Issuer                    6.1.3
   ------------------------------------------------------
   6.1.4 CA Public Key Delivery to Users       6.1.4
   ------------------------------------------------------
   6.1.5 Key Sizes                             6.1.5
   ------------------------------------------------------
   6.1.6 Public Key Parameters Generation      6.1.6
   ------------------------------------------------------
   6.1.7 Parameter Quality Checking            6.1.6
   ------------------------------------------------------
   6.1.8 Hardware/Software Key Generation      6.1.1
   ------------------------------------------------------
   6.1.9 Key Usage Purposes
         (as per X.509 v3 Key Usage Field)     6.1.9
   ------------------------------------------------------
   6.2 Private Key Protection                  6.2
   ------------------------------------------------------
   6.2.1 Standards for Cryptographic
         Module                                6.2.1
   ------------------------------------------------------

   6.2.2 Private Key (n out of m)
         Multi-Person Control                  6.2.2
   ------------------------------------------------------
   6.2.3 Private Key Escrow                    6.2.3
   ------------------------------------------------------
   6.2.4 Private Key Backup                    6.2.4
   ------------------------------------------------------
   6.2.5 Private Key Archival                  6.2.5
   ------------------------------------------------------
   6.2.6 Private Key Entry Into
         Cryptographic Module              6.2.6, 6.2.7
   ------------------------------------------------------
   6.2.7 Method of Activating
         Private Key                           6.2.8

   ------------------------------------------------------
   6.2.8 Method of Deactivating
         Private Key                           6.2.9
   ------------------------------------------------------
   6.2.9 Method of Destroying Private
         Key                                   6.2.10
   ------------------------------------------------------
   6.3 Other Aspects of Key Pair
       Management                              6.3
   ------------------------------------------------------
   6.3.1 Public Key Archival                   6.3.1
   ------------------------------------------------------
   6.3.2 Usage Periods for the Public
         and Private Keys                      6.3.2
   ------------------------------------------------------
   6.4 Activation Data                         6.4
   ------------------------------------------------------
   6.4.1 Activation Data Generation
         and Installation                      6.4.1
   ------------------------------------------------------
   6.4.2 Activation Data Protection            6.4.2
   ------------------------------------------------------
   6.4.3 Other Aspects of Activation
         Data                                  6.4.3
   ------------------------------------------------------
   6.5 Computer Security Controls              6.5
   ------------------------------------------------------
   6.5.1 Specific Computer Security
         Technical Requirements                6.5.1
   ------------------------------------------------------
   6.5.2 Computer Security Rating              6.5.2
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容