RFC 3647 - Internet X.509 Public Key Infrastructure Certific(9)

时间:2006-10-21 来源: 作者: 点击:
------------------------------------------------------ 5.3.1Qualifications,Experience, andClearanceRequirements5.3.1 ------------------------------------------------------ 5.3.2BackgroundCheckProcedu
  
   ------------------------------------------------------
   5.3.1 Qualifications, Experience,
         and Clearance Requirements         5.3.1
   ------------------------------------------------------
   5.3.2 Background Check Procedures        5.3.2
   ------------------------------------------------------
   5.3.3 Training Requirements              5.3.3
   ------------------------------------------------------
   5.3.4 Retraining Frequency
         and Requirements                   5.3.4
   ------------------------------------------------------
   5.3.5 Job Rotation Frequency
         and Sequence                       5.3.5
   ------------------------------------------------------
   5.3.6 Sanctions for Unauthorized
         Actions                            5.3.6

   ------------------------------------------------------
   5.3.7 Independent Contractor
         Requirements                       5.3.7
   ------------------------------------------------------
   5.3.8 Documentation Supplied to
         Personnel                          5.3.8
   ------------------------------------------------------
   5.4 Audit Logging Procedures             4.5
   ------------------------------------------------------
   5.4.1 Types of Events Recorded           4.5.1
   ------------------------------------------------------
   5.4.2 Frequency of Processing Log        4.5.2
   ------------------------------------------------------
   5.4.3 Retention Period for Audit
         Log                                4.5.3
   ------------------------------------------------------
   5.4.4 Protection of Audit Log            4.5.4
   ------------------------------------------------------
   5.4.5 Audit Log Backup Procedures        4.5.5
   ------------------------------------------------------
   5.4.6 Audit Collection System
         (Internal vs. External)            4.5.6
   ------------------------------------------------------
   5.4.7 Notification to Event-Causing
         Subject                            4.5.7
   ------------------------------------------------------
   5.4.8 Vulnerability Assessments          4.5.8
   ------------------------------------------------------
   5.5 Records Archival                     4.6
   ------------------------------------------------------
   5.5.1 Types of Records Archived          4.6.1
   ------------------------------------------------------
   5.5.2 Retention Period for Archive       4.6.2
   ------------------------------------------------------
   5.5.3 Protection of Archive              4.6.3
   ------------------------------------------------------
   5.5.4 Archive Backup Procedures          4.6.4
   ------------------------------------------------------
   5.5.5 Requirements for Time-Stamping
         of Records                         4.6.5
   ------------------------------------------------------
   5.5.6 Archive Collection System
         (Internal or External)             4.6.6
   ------------------------------------------------------
   5.5.7 Procedures to Obtain and
         Verify Archive
         Information                        4.6.7

   ------------------------------------------------------
   5.6 Key Changeover                       4.7
   ------------------------------------------------------
   5.7 Compromise and Disaster Recovery     4.8
   ------------------------------------------------------
   5.7.1 Incident and Compromise
         Handling Procedures                4.8
   ------------------------------------------------------
   5.7.2 Computing Resources, Software,
         and/or Data Are Corrupted          4.8.1
   ------------------------------------------------------
   5.7.3 Entity Private Key
         Compromise Procedures              4.8.3
   ------------------------------------------------------
   5.7.4 Business Continuity
         Capabilities After a
         Disaster                           4.8.4
   ------------------------------------------------------
   5.8 CA or RA Termination                 4.9
   ------------------------------------------------------
   6. Technical Security Controls           2.1.3, 2.1.4,
                                            6.
   ------------------------------------------------------
   6.1 Key Pair Generation and
       Installation                         6.1
   ------------------------------------------------------
   6.1.1 Key Pair Generation                6.1.1, 6.1.8
   ------------------------------------------------------
   6.1.2 Private Key Delivery to
         Subscriber                         6.1.2
   ------------------------------------------------------
   6.1.3 Public Key Delivery to
         Certificate Issuer                 6.1.3
   ------------------------------------------------------
   6.1.4 CA Public Key Delivery to
         Relying Parties                    6.1.4
   ------------------------------------------------------
   6.1.5 Key Sizes                          6.1.5
   ------------------------------------------------------
   6.1.6 Public Key Parameters Generation
         and Quality Checking               6.1.6, 6.1.7
   ------------------------------------------------------
   6.1.7 Key Usage Purposes
         (as per X.509 v3
         Key Usage Field)                   6.1.9

   ------------------------------------------------------
   6.2   Private Key Protection and
         Cryptographic Module
         Engineering Controls               6.2, 6.8
   ------------------------------------------------------
   6.2.1 Cryptographic Module Standards
         and Controls                       6.2.1, 6.8
   ------------------------------------------------------
   6.2.2 Private Key (n out of m)
         Multi-Person Control               6.2.2
   ------------------------------------------------------
   6.2.3 Private Key Escrow                 6.2.3
   ------------------------------------------------------
   6.2.4 Private Key Backup                 6.2.4
   ------------------------------------------------------
   6.2.5 Private Key Archival               6.2.5
   ------------------------------------------------------
   6.2.6 Private Key Transfer Into
         or From a Cryptographic
         Module                             6.2.6
   ------------------------------------------------------
   6.2.7 Private Key Storage on
         Cryptographic Module               6.2.6
   ------------------------------------------------------
   6.2.8 Method of Activating Private
         Key                                6.2.7
   ------------------------------------------------------
   6.2.9 Method of Deactivating
         Private Key                        6.2.8
   ------------------------------------------------------
   6.2.10 Method of Destroying
          Private Key                       6.2.9
   ------------------------------------------------------
   6.2.11 Cryptographic Module Rating       6.2.1, 6.8
   ------------------------------------------------------
   6.3 Other Aspects of Key Pair
       Management                           6.3
   ------------------------------------------------------
   6.3.1 Public Key Archival                6.3.1
   ------------------------------------------------------
   6.3.2 Certificate Operational
         Periods and Key Pair Usage
         Periods                            6.3.2
   ------------------------------------------------------
   6.4 Activation Data                      6.4

   ------------------------------------------------------
   6.4.1 Activation Data Generation
         and Installation                   6.4.1
   ------------------------------------------------------
   6.4.2 Activation Data Protection         6.4.2
   ------------------------------------------------------
   6.4.3 Other Aspects of Activation
         Data                               6.4.3
   ------------------------------------------------------
   6.5 Computer Security Controls           6.5
   ------------------------------------------------------
   6.5.1 Specific Computer Security
         Technical Requirements             6.5.1
   ------------------------------------------------------
   6.5.2 Computer Security Rating           6.5.2
   ------------------------------------------------------
   6.6 Life Cycle Technical Controls        6.6
   ------------------------------------------------------
   6.6.1 System Development Controls        6.6.1
   ------------------------------------------------------
   6.6.2 Security Management Controls       6.6.2
   ------------------------------------------------------
   6.6.3 Life Cycle Security Controls       6.6.3
   ------------------------------------------------------
   6.7 Network Security Controls            6.7
   ------------------------------------------------------
   6.8 Time-Stamping                        N/A
   ------------------------------------------------------
   7. Certificate, CRL, and
      OCSP Profiles                         7.
   ------------------------------------------------------
   7.1 Certificate Profile                  7.1
   ------------------------------------------------------
   7.1.1 Version Number(s)                  7.1.1
   ------------------------------------------------------
   7.1.2 Certificate Extensions             7.1.2
   ------------------------------------------------------
   7.1.3 Algorithm Object Identifiers       7.1.3
   ------------------------------------------------------
   7.1.4 Name Forms                         7.1.4
   ------------------------------------------------------
   7.1.5 Name Constraints                   7.1.5
   ------------------------------------------------------
   7.1.6 Certificate Policy
         Object Identifier                  7.1.6
   ------------------------------------------------------
   7.1.7 Usage of Policy Constraints
         Extension                          7.1.7

   ------------------------------------------------------
   7.1.8 Policy Qualifiers Syntax
         and Semantics                      7.1.8
   ------------------------------------------------------
   7.1.9 Processing Semantics for the
         Critical Certificate Policies
         Extension                          7.1.9
   ------------------------------------------------------
   7.2 CRL Profile                          7.2
   ------------------------------------------------------
   7.2.1 Version Number(s)                  7.2.1
   ------------------------------------------------------
   7.2.2 CRL and CRL Entry Extensions       7.2.1
   ------------------------------------------------------
   7.3 OCSP Profile                         N/A
   ------------------------------------------------------
   7.3.1 Version Number(s)                  N/A
   ------------------------------------------------------
   7.3.2 OCSP Extensions                    N/A
   ------------------------------------------------------
   8. Compliance Audit and Other
      Assessments                           2.7
   ------------------------------------------------------
   8.1 Frequency and Circumstances
       of Assessment                        2.7.1
   ------------------------------------------------------
   8.2 Identity/Qualifications of
       Assessor                             2.7.2
   ------------------------------------------------------
   8.3 Assessor’s Relationship to
       Assessed Entity                      2.7.3
   ------------------------------------------------------
   8.4 Topics Covered by Assessment         2.7.4
   ------------------------------------------------------
   8.5 Actions Taken as a Result
       of Deficiency                        2.7.5
   ------------------------------------------------------
   8.6 Communications of Results            2.7.6
   ------------------------------------------------------
   9. Other Business and Legal
      Matters                               2.

   ------------------------------------------------------
   9.1 Fees                                 2.5
   ------------------------------------------------------
   9.1.1 Certificate Issuance or
         Renewal Fees                       2.5.1

   ------------------------------------------------------
   9.1.2 Certificate Access Fees            2.5.2
   ------------------------------------------------------
   9.1.3 Revocation or Status
         Information Access Fees            2.5.3
   ------------------------------------------------------
   9.1.4 Fees for Other Services            2.5.4
   ------------------------------------------------------
   9.1.5 Refund Policy                      2.5.5
   ------------------------------------------------------
   9.2 Financial Responsibility             2.3
   ------------------------------------------------------
   9.2.1 Insurance Coverage                 2.3
   ------------------------------------------------------
   9.2.2 Other Assets                       2.3
   ------------------------------------------------------
   9.2.3 Insurance or Warranty Coverage
         for End-Entities                   2.3
   ------------------------------------------------------
   9.3 Confidentiality of Business
       Information                          2.8
   ------------------------------------------------------
   9.3.1 Scope of Confidential
         Information                        2.8.1, 2.8.3
   ------------------------------------------------------
   9.3.2 Information Not Within the
         Scope of Confidential
         Information                        2.8.2, 2.8.3
   ------------------------------------------------------
   9.3.3 Responsibility to Protect
         Confidential Information           2.8,

                                            2.8.3-2.8.7
   ------------------------------------------------------
   9.4 Privacy of Personal Information      2.8
   ------------------------------------------------------
   9.4.1 Privacy Plan                       N/A
   ------------------------------------------------------
   9.4.2 Information Treated as Private     2.8.1, 2.8.3
   ------------------------------------------------------
   9.4.3 Information Not Deemed Private     2.8.2, 2.8.3
   ------------------------------------------------------
   9.4.4 Responsibility to Protect
         Private Information                2.8, 2.8.1,
                                            2.8.3
   ------------------------------------------------------
   9.4.5 Notice and Consent to Use
         Private Information                N/A

   ------------------------------------------------------
   9.4.6 Disclosure Pursuant to
         Judicial or Administrative
         Process                            2.8.4-2.8.5
   ------------------------------------------------------
   9.4.7 Other Information Disclosure
         Circumstances                      2.8.6-2.8.7
   ------------------------------------------------------
   9.5 Intellectual Property rights         2.9
   ------------------------------------------------------
   9.6 Representations and Warranties       2.2
   ------------------------------------------------------
   9.6.1 CA Representations and
         Warranties                         2.2.1
   ------------------------------------------------------
   9.6.2 RA Representations and
         Warranties                         2.2.2
   ------------------------------------------------------
   9.6.3 Subscriber Representations
         and Warranties                     2.1.3
   ------------------------------------------------------

   9.6.4 Relying Party Representations
         and Warranties                     2.1.4
   ------------------------------------------------------
   9.6.5 Representations and Warranties
         of Other Participants                 N/A
   ------------------------------------------------------
   9.7 Disclaimers of Warranties            2.2, 2.3.2
   ------------------------------------------------------
   9.8 Limitations of Liability                2.2
   ------------------------------------------------------
   9.9 Indemnities                          2.1.3, 2.1.4,
                                            2.2, 2.3.1
   ------------------------------------------------------
   9.10 Term and Termination                   N/A
   ------------------------------------------------------
   9.10.1 Term                                 N/A
   ------------------------------------------------------
   9.10.2 Termination                          N/A
   ------------------------------------------------------
   9.10.3 Effect of Termination and
          Survival                             N/A
   ------------------------------------------------------
   9.11 Individual Notices and
        Communications with Participants       2.4.2
   ------------------------------------------------------
   9.12 Amendments                             8.1

   ------------------------------------------------------
   9.12.1 Procedure for Amendment              8.1
   ------------------------------------------------------
   9.12.2 Notification Mechanism
          and Period                           8.1
   ------------------------------------------------------
   9.12.3 Circumstances Under Which OID
          Must be Changed                      8.1
   ------------------------------------------------------
   9.13 Dispute Resolution Provisions          2.4.3
   ------------------------------------------------------
   9.14 Governing Law                          2.4.1
   ------------------------------------------------------
   9.15 Compliance with Applicable Law         2.4.1
   ------------------------------------------------------
   9.16 Miscellaneous Provisions               2.4
   ------------------------------------------------------
   9.16.1 Entire Agreement                     2.4.2
   ------------------------------------------------------
   9.16.2 Assignment                           N/A
   ------------------------------------------------------
   9.16.3 Severability                         2.4.2
   ------------------------------------------------------
   9.16.4 Enforcement (Attorney’s Fees
          and Waiver of Rights)                2.4.3
   ------------------------------------------------------
   9.17 Other Provisions                       N/A
   ------------------------------------------------------

8.   Acknowledgements

   The development of the predecessor document (RFC 2527) was supported
   by the Government of Canada’s Policy Management Authority (PMA)
   Committee, the National Security Agency, the National Institute of
   Standards and Technology (NIST), and the American Bar Association
   Information Security Committee Accreditation Working Group.

   This revision effort is largely a result of constant inspiration from
   Michael Baum.  Michael Power, Mike Jenkins, and Alice Sturgeon have
   also made several contributions.

9.  References

   [ABA1] American Bar Association, Digital Signature Guidelines: Legal
          Infrastructure for Certification Authorities and Secure
          Electronic Commerce, 1996.

   [ABA2] American Bar Association, PKI Assessment Guidelines, v0.30,
          Public Draft For Comment, June 2001.

   [BAU1] Michael. S. Baum, Federal Certification Authority Liability
          and Policy, NIST-GCR-94-654, June 1994, available at
          http://www.verisign.com/repository/pubs/index.html.

   [ETS]  European Telecommunications Standards Institute, "Policy
          Requirements for Certification Authorities Issuing Qualified
          Certificates," ETSI TS 101 456, Version 1.1.1, December 2000.

   [GOC]  Government of Canada PKI Policy Management Authority, "Digital
          Signature and Confidentiality Certificate Policies for the
          Government of Canada Public Key Infrastructure," v.3.02, April
          1999.

   [IDT]  Identrus, LLC, "Identrus Identity Certificate Policy" IP-IPC
          Version 1.7, March 2001.

   [ISO1] ISO/IEC 9594-8/ITU-T Recommendation X.509, "Information
          Technology - Open Systems Interconnection: The Directory:
          Authentication Framework," 1997 edition. (Pending publication
          of 2000 edition, use 1997 edition.)

   [PEM1] Kent, S., "Privacy Enhancement for Internet Electronic Mail:
          Part II: Certificate-Based Key Management", RFC 1422, February
          1993.

   [PKI1] Housley, R., Polk, W. Ford, W. and D. Solo, "Internet X.509
          Public Key Infrastructure Certificate and Certificate
          Revocation List (CRL) Profile", RFC 3280, April 2002.

   [CPF]  Chokhani, S. and W. Ford, "Internet X.509 Public Key
          Infrastructure, Certificate Policy and Certification Practices
          Statement Framework", RFC 2527, March 1999.

10.  Notes

   1.  A paper copy of the ABA Digital Signature Guidelines can be
       purchased from the ABA.  See http://www.abanet.com for ordering
       details.  The DSG may also be downloaded without charge from the
       ABA website at
       http://www.abanet.org/scitech/ec/isc/digital_signature.html.

   2.  A draft of the PKI Assessment Guidelines may be downloaded
       without charge from the ABA website at
       http://www.abanet.org/scitech/ec/isc/pag/pag.html.

   3.  The term "meaningful" means that the name form has commonly
       understood semantics to determine the identity of a person and/or
       organization.  Directory names and RFC 822 names may be more or
       less meaningful.

   4.  The subject may not need to prove to the CA that the subject has
       possession of the private key corresponding to the public key
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容