RFC 3647 - Internet X.509 Public Key Infrastructure Certific(8)

时间:2006-10-21 来源: 作者: 点击:
------------------------------------------------------ 6.6LifeCycleTechnicalControls6.6 ------------------------------------------------------ 6.6.1SystemDevelopmentControls6.6.1 --------------------
  
   ------------------------------------------------------
   6.6 Life Cycle Technical Controls           6.6
   ------------------------------------------------------
   6.6.1 System Development Controls           6.6.1
   ------------------------------------------------------
   6.6.2 Security Management Controls          6.6.2
   ------------------------------------------------------
   6.6.3 Life Cycle Security Controls          6.6.3
   ------------------------------------------------------
   6.7 Network Security Controls               6.7
   ------------------------------------------------------
   6.8 Cryptographic Module
       Engineering Controls                 6.2.1, 6.2,
                                            6.2.1, 6.2.11
   ------------------------------------------------------
   7.Certificate and CRL Profiles              7.

   ------------------------------------------------------
   7.1 Certificate Profile                     7.1
   ------------------------------------------------------
   7.1.1 Version Number(s)                     7.1.1
   ------------------------------------------------------
   7.1.2 Certificate Extensions                7.1.2
   ------------------------------------------------------
   7.1.3 Algorithm Object Identifiers          7.1.3
   ------------------------------------------------------
   7.1.4 Name Forms                            7.1.4
   ------------------------------------------------------
   7.1.5 Name Constraints                      7.1.5
   ------------------------------------------------------
   7.1.6 Certificate Policy Object
         Identifier                            7.1.6
   ------------------------------------------------------
   7.1.7 Usage of Policy Constraints
         Extension                             7.1.7
   ------------------------------------------------------
   7.1.8 Policy Qualifiers Syntax
         and Semantics                         7.1.8
   ------------------------------------------------------
   7.1.9 Processing Semantics for
         the Critical Certificate
         Policies Extension                    7.1.9
   ------------------------------------------------------
   7.2 CRL Profile                             7.2
   ------------------------------------------------------
   7.2.1 Version Number(s)                     7.2.1
   ------------------------------------------------------
   7.2.2 CRL and CRL Entry Extensions          7.2.1
   ------------------------------------------------------
   8. Specification Administration             N/A
   ------------------------------------------------------
   8.1 Specification Change
       Procedures                              9.12
   ------------------------------------------------------
   8.2 Publication and Notification
       Policies                                2.2, 2.3
   ------------------------------------------------------
   8.3 CPS Approval Procedures                 1.5.4
   ------------------------------------------------------

   The following matrix shows the sections in the new framework and the
   sections in RFC 2527 to which the headings in the new framework
   correspond.

   NEW RFC SECTION                      ORIGINAL RFC 2527
                                             SECTION
   ------------------------------------------------------
   1. Introduction                             1.
   ------------------------------------------------------
   1.1 Overview                                1.1
   ------------------------------------------------------
   1.2 Document Name and Identification        1.2
   ------------------------------------------------------
   1.3 PKI Participants                        1.3
   ------------------------------------------------------
   1.3.1 Certification Authorities             1.3.1
   ------------------------------------------------------
   1.3.2 Registration Authorities              1.3.2
   ------------------------------------------------------
   1.3.3 Subscribers                           1.3.3
   ------------------------------------------------------
   1.3.4 Relying Parties                       1.3.3
   ------------------------------------------------------
   1.3.5 Other Participants                    N/A
   ------------------------------------------------------
   1.4 Certificate Usage                       1.3.4
   ------------------------------------------------------
   1.4.1 Appropriate Certificate Uses          1.3.4
   ------------------------------------------------------
   1.4.2 Prohibited Certificate Uses           1.3.4
   ------------------------------------------------------
   1.5 Policy Administration                   1.4
   ------------------------------------------------------
   1.5.1 Organization Administering
         the Document                          1.4.1
   ------------------------------------------------------
   1.5.2 Contact Person                        1.4.2
   ------------------------------------------------------
   1.5.3 Person Determining CPS
         Suitability for the Policy            1.4.3
   ------------------------------------------------------
   1.5.4 CPS Approval Procedures               8.3
   ------------------------------------------------------
   1.6 Definitions and Acronyms                N/A
   ------------------------------------------------------
   2. Publication and Repository
      Responsibilities                         2.1.5, 2.6

   ------------------------------------------------------
   2.1 Repositories                            2.6.4
   ------------------------------------------------------
   2.2 Publication of Certification
       Information                             2.6.1, 8.2
   ------------------------------------------------------
   2.3 Time or Frequency of
       Publication                             2.6.2, 8.2
   ------------------------------------------------------
   2.4 Access Controls on Repositories         2.6.3
   ------------------------------------------------------
   3. Identification and Authentication        3.
   ------------------------------------------------------
   3.1 Naming                                  3.1
   ------------------------------------------------------
   3.1.1 Type of Names                         3.1.1
   ------------------------------------------------------
   3.1.2 Need for Names to be Meaningful       3.1.2
   ------------------------------------------------------
   3.1.3. Anonymity or Pseudonymity of
          Subscribers                          3.1.2
   ------------------------------------------------------
   3.1.4 Rules for Interpreting Various
         Name Forms                            3.1.3
   ------------------------------------------------------
   3.1.5 Uniqueness of Names                   3.1.4
   ------------------------------------------------------
   3.1.6 Recognition, Authentication,
         and Role of Trademarks           3.1.5, 3.1.6
   ------------------------------------------------------
   3.2 Initial Identity Validation             3.1
   ------------------------------------------------------
   3.2.1 Method to Prove Possession
         of Private Key                        3.1.7
   ------------------------------------------------------
   3.2.2 Authentication of
         Organization Identity                 3.1.8
   ------------------------------------------------------
   3.2.3 Authentication of Individual
         Identity                              3.1.9
   ------------------------------------------------------
   3.2.4 Non-Verified Subscriber
         Information                           N/A
   ------------------------------------------------------
   3.2.5 Validation of Authority               3.1.9

   ------------------------------------------------------
   3.2.6 Criteria for Interoperation           4.1
   ------------------------------------------------------
   3.3 Identification and Authentication
       for Re-Key Requests                     3.2, 3.3
   ------------------------------------------------------
   3.3.1 Identification and
         Authentication for Routine
         Re-Key                                3.2
   ------------------------------------------------------
   3.3.2 Identification and
         Authentication for Re-Key
         After Revocation                      3.3
   ------------------------------------------------------
   3.4 Identification and Authentication
       for Revocation Request                  3.4
   ------------------------------------------------------
   4. Certificate Life-Cycle
      Operational Requirements                 4.
   ------------------------------------------------------
   4.1 Certificate Application                 4.1
   ------------------------------------------------------
   4.1.1 Who Can Submit a Certificate
         Application                           4.1
   ------------------------------------------------------
   4.1.2 Enrollment Process and
         Responsibilities                      2.1.3, 4.1
   ------------------------------------------------------
   4.2 Certificate Application
       Processing                              4.1, 4.2
   ------------------------------------------------------
   4.2.1 Performing Identification
         and Authentication Functions          4.1, 4.2
   ------------------------------------------------------
   4.2.2 Approval or Rejection of
         Certificate Applications              4.1, 4.2
   ------------------------------------------------------
   4.2.3 Time to Process
         Certificate Applications              4.1, 4.2
   ------------------------------------------------------
   4.3 Certificate Issuance                    4.2
   ------------------------------------------------------
   4.3.1 CA Actions During
         Certificate Issuance                  4.2
   ------------------------------------------------------
   4.3.2 Notifications to Subscriber by
         the CA of Issuance of Certificate     4.2, 4.3

   ------------------------------------------------------
   4.4 Certificate Acceptance                  2.1.3, 4.3
   ------------------------------------------------------
   4.4.1 Conduct Constituting
         Certificate Acceptance                4.3
   ------------------------------------------------------
   4.4.2 Publication of the
         Certificate by the CA          2.1.5, 2.6.1, 4.3
   ------------------------------------------------------
   4.4.3 Notification of
         Certificate Issuance by
         the CA to Other Entities       2.1.5, 2.6.1,
                                        4.2, 4.3
   ------------------------------------------------------
   4.5 Key Pair and
       Certificate Usage                1.3.4, 2.1.3,
                                        2.1.4
   ------------------------------------------------------
   4.5.1 Subscriber Private Key
         and Certificate Usage          1.3.4, 2.1.3
   ------------------------------------------------------
   4.5.2 Relying Party Public
         Key and Certificate
         Usage                          1.3.4, 2.1.4
   ------------------------------------------------------
   4.6 Certificate Renewal              3.2, 4.1, 4.2,
                                        4.3
   ------------------------------------------------------
   4.6.1 Circumstances for
         Certificate Renewal            3.2, 4.1
   ------------------------------------------------------
   4.6.2 Who May Request Renewal        3.2, 4.1
   ------------------------------------------------------
   4.6.3 Processing Certificate
         Renewal Requests               3.2, 4.1, 4.2
   ------------------------------------------------------
   4.6.4 Notification of New
         Certificate Issuance to
         Subscriber                     3.2, 4.2, 4.3
   ------------------------------------------------------
   4.6.5 Conduct Constituting
         Acceptance of a Renewal
         Certificate                    2.1.3, 3.2, 4.3
   ------------------------------------------------------
   4.6.6 Publication of the
         Renewal Certificate
         by the CA                      2.1.5, 2.6.1,
                                        3.2, 4.3

   ------------------------------------------------------
   4.6.7 Notification of
         Certificate Issuance by
         the CA to Other Entities       2.1.5, 2.6.1, 3.2,
                                        4.2, 4.3
   ------------------------------------------------------
   4.7 Certificate Re-Key               3.2, 4.1, 4.2, 4.3
   ------------------------------------------------------
   4.7.1 Circumstances for
         Certificate Re-Key             3.2, 4.1
   ------------------------------------------------------
   4.7.2 Who May Request Certification
         of a New Public Key            3.2, 4.1
   ------------------------------------------------------
   4.7.3 Processing Certificate
         Re-Keying Requests             3.2, 4.1, 4.2
   ------------------------------------------------------
   4.7.4 Notification of New
         Certificate Issuance to
         Subscriber                     3.2, 4.2, 4.3
   ------------------------------------------------------
   4.7.5 Conduct Constituting
         Acceptance of a
         Re-Keyed Certificate           2.1.3, 3.2, 4.3
   ------------------------------------------------------
   4.7.6 Publication of the
         Re-Keyed Certificate
         by the CA                      2.1.5, 2.6.1,
                                        3.2, 4.3
   ------------------------------------------------------
   4.7.7 Notification of Certificate
         Issuance by the CA
         to Other Entities              2.1.5, 2.6.1,
                                        3.2, 4.2, 4.3
   ------------------------------------------------------
   4.8 Certificate Modification                4.4
   ------------------------------------------------------
   4.8.1 Circumstances for
         Certificate Modification       2.1.3, 4.4.1
   ------------------------------------------------------
   4.8.2 Who May Request Certificate
         Modification                   4.4.2
   ------------------------------------------------------
   4.8.3 Processing Certificate
         Modification Requests          4.4.3

   ------------------------------------------------------
   4.8.4 Notification of New
         Certificate Issuance to
         Subscriber                     4.2, 4.3, 4.4.3
   ------------------------------------------------------
   4.8.5 Conduct Constituting
         Acceptance of Modified
         Certificate                    2.1.3, 4.3, 4.4.3
   ------------------------------------------------------
   4.8.6 Publication of the Modified
         Certificate by
         the CA                         2.1.5, 2.6.1,
                                        4.2, 4.3, 4.4.3
   ------------------------------------------------------
   4.8.7 Notification of
         Certificate Issuance by
         the CA to Other
         Entities                       2.1.5, 2.6.1,
                                        4.2, 4.3, 4.4.3
   ------------------------------------------------------
   4.9 Certificate Revocation
       and Suspension                          4.4
   ------------------------------------------------------
   4.9.1 Circumstances for Revocation   2.1.3, 4.4.1
   ------------------------------------------------------
   4.9.2 Who Can Request Revocation     4.4.2
   ------------------------------------------------------
   4.9.3 Procedure for Revocation
         Request                        2.1.3, 4.4.3
   ------------------------------------------------------
   4.9.4 Revocation Request Grace
         Period                                4.4.4
   ------------------------------------------------------
   4.9.5 Time Within Which CA Must
         Process the Revocation Request    N/A
   ------------------------------------------------------
   4.9.6 Revocation Checking
         Requirements for Relying
         Parties                         2.1.4, 4.4.10,
                                         4.4.12, 4.4.14
   ------------------------------------------------------
   4.9.7 CRL Issuance Frequency          4.4.9, 4.8.3
   ------------------------------------------------------
   4.9.8 Maximum Latency for CRLs        4.4.9
   ------------------------------------------------------
   4.9.9 On-Line Revocation/Status
         Checking Availability           4.4.11, 4.8.3

   ------------------------------------------------------
   4.9.10 On-Line Revocation
          Checking Requirements          4.4.12
   ------------------------------------------------------
   4.9.11 Other Forms of Revocation
          Advertisements Available       4.4.13, 4.4.14,
                                         4.8.3
   ------------------------------------------------------
   4.9.12 Special Requirements re
          Key Compromise                 4.4.15
   ------------------------------------------------------
   4.9.13 Circumstances for Suspension   2.1.3, 4.4.5
   ------------------------------------------------------
   4.9.14 Who Can Request Suspension     4.4.6
   ------------------------------------------------------
   4.9.15 Procedure for
          Suspension Request             2.1.3, 4.4.7
   ------------------------------------------------------
   4.9.16 Limits on Suspension Period    4.4.8
   ------------------------------------------------------
   4.10 Certificate Status Services      4.4.9-4.4.14
   ------------------------------------------------------
   4.10.1 Operational
          Characteristics                4.4.9, 4.4.11,
                                         4.4.13
   ------------------------------------------------------
   4.10.2 Service Availability           4.4.9, 4.4.11,
                                         4.4.13
   ------------------------------------------------------
   4.10.3 Operational Features           4.4.9, 4.4.11,
                                         4.4.13
   ------------------------------------------------------
   4.11 End of Subscription                       N/A
   ------------------------------------------------------
   4.12 Key Escrow and Recovery                  6.2.3
   ------------------------------------------------------
   4.12.1 Key Escrow and Recovery Policy
          and Practices                          6.2.3
   ------------------------------------------------------
   4.12.2 Session Key Encapsulation
          and Recovery Policy and
          Practices                              6.2.3
   ------------------------------------------------------
   5. Facility, Management, and
      Operational Controls               2.1.3, 2.1.4,
                                         4., 5.
   ------------------------------------------------------
   5.1 Physical Controls                         5.1

   ------------------------------------------------------
   5.1.1 Site Location and Construction          5.1.1
   ------------------------------------------------------
   5.1.2 Physical Access                         5.1.2
   ------------------------------------------------------
   5.1.3 Power and Air Conditioning              5.1.3
   ------------------------------------------------------
   5.1.4 Water Exposures                         5.1.4
   ------------------------------------------------------
   5.1.5 Fire Prevention and Protection          5.1.5
   ------------------------------------------------------
   5.1.6 Media Storage                           5.1.6
   ------------------------------------------------------
   5.1.7 Waste Disposal                          5.1.7
   ------------------------------------------------------
   5.1.8 Off-Site Backup                         5.1.8
   ------------------------------------------------------
   5.2 Procedural Controls                       5.2
   ------------------------------------------------------
   5.2.1 Trusted Roles                           5.2.1
   ------------------------------------------------------
   5.2.2 Number of Persons Required
         per Task                                5.2.2
   ------------------------------------------------------
   5.2.3 Identification and
         Authentication for Each Role            5.2.3
   ------------------------------------------------------
   5.2.4 Roles Requiring Separation
         of Duties                          5.2.1, 5.2.2
   ------------------------------------------------------
   5.3 Personnel Controls                        5.3
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容