ETSI TR 102 437-2006 Electronic Signatures and Infrastructures (ESI) Guidance on TS 101 456 (Policy Requirements for certification authorities issuing qualified certificates) (V1 1.pdf
《ETSI TR 102 437-2006 Electronic Signatures and Infrastructures (ESI) Guidance on TS 101 456 (Policy Requirements for certification authorities issuing qualified certificates) (V1 1.pdf》由会员分享,可在线阅读,更多相关《ETSI TR 102 437-2006 Electronic Signatures and Infrastructures (ESI) Guidance on TS 101 456 (Policy Requirements for certification authorities issuing qualified certificates) (V1 1.pdf(73页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TR 102 437 V1.1.1 (2006-10)Technical Report Electronic Signatures and Infrastructures (ESI); Guidance on TS 101 456 (Policy Requirements for certification authorities issuing qualified certificates) ETSI ETSI TR 102 437 V1.1.1 (2006-10) 2 Reference DTR/ESI-000023 Keywords e-commerce, electroni
2、c signature, security ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of the
3、present document can be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In c
4、ase of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this
5、and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as author
6、ized by written permission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2006. All rights reserved. DECTTM, PLUGTESTSTM and UMTSTM are Trade Marks of ETSI registered for the benefit of its Members. TIPHONTMand the TI
7、PHON logo are Trade Marks currently being registered by ETSI for the benefit of its Members. 3GPPTM is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. ETSI ETSI TR 102 437 V1.1.1 (2006-10) 3 Contents Intellectual Property Rights5 Foreword.5 Int
8、roduction 5 1 Scope 7 2 References 7 3 Definitions and abbreviations.9 3.1 Definitions9 3.2 Abbreviations .9 3.3 Additional terms used in the present document9 4 General Concepts .10 5 Introduction to qualified certificate policies.10 5.1 Overview 10 5.2 Identification 11 5.3 User Community and appl
9、icability.11 5.3.1 QCP public + SSCD .12 5.3.2 QCP public12 5.4 Conformance 12 5.4.1 General12 5.4.2 QCP public + SSCD .14 5.4.3 QCP public14 6 Obligations and liability .14 6.1 Certification authority obligations14 6.2 Subscriber obligations 15 6.3 Information for Relying parties 17 6.4 Liability 1
10、8 7 Requirements on CA practice.18 7.1 Certification practice statement19 7.2 Public key infrastructure - Key management life cycle21 7.2.1 Certification authority key generation 21 7.2.2 Certification authority key storage, backup and recovery.24 7.2.3 Certification authority public key distributio
11、n27 7.2.4 Key escrow .27 7.2.5 Certification authority key usage 27 7.2.6 End of CA key life cycle.28 7.2.7 Life cycle management of cryptographic hardware used to sign certificates .29 7.2.8 CA provided subject key management services30 7.2.9 Secure-signature-creation device preparation.31 7.3 Publ
12、ic key infrastructure - Certificate Management life cycle .32 7.3.1 Subject registration .32 7.3.2 Certificate renewal, rekey and update.36 7.3.3 Certificate generation37 7.3.4 Dissemination of Terms and Conditions.39 7.3.5 Certificate dissemination 40 7.3.6 Certificate revocation and suspension.41
13、7.4 CA management and operation 44 7.4.1 Security management44 7.4.2 Asset classification and management .48 7.4.3 Personnel security.49 7.4.4 Physical and environmental security.52 7.4.5 Operations management .54 7.4.6 System Access Management.56 ETSI ETSI TR 102 437 V1.1.1 (2006-10) 4 7.4.7 Trustw
14、orthy Systems Deployment and Maintenance .58 7.4.8 Business continuity management and incident handling 59 7.4.9 CA termination .62 7.4.10 Compliance with Legal Requirements63 7.4.11 Recording of Information Concerning Qualified Certificates.65 7.5 Organizational 67 8 Framework for the definition of
15、 other qualified certificate policies 69 8.1 Qualified certificate policy management69 8.2 Exclusions for non public QCPs.70 8.3 Additional requirements .71 8.4 Conformance 71 History 73 ETSI ETSI TR 102 437 V1.1.1 (2006-10) 5 Intellectual Property Rights IPRs essential or potentially essential to t
16、he present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETS
17、I in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (http:/webapp.etsi.org/IPR/home.asp). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given
18、as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document. Foreword This Technical Report (TR) has been produced by ETSI Technical Committee Security (SEC). The present document i
19、s largely based on the “TTP.NL Guidance on TS 101 456 15“, issued by ECP.NL - The Electronic Commerce Platform for the Netherlands that kindly offered their document as a basis for the present document. Introduction Electronic commerce is getting momentum as a way of doing business and communicating
20、 across public and private networks. An important requirement of electronic commerce is the ability to identify the originator of electronic information in the same way that documents are signed using a hand-written signature. This is commonly achieved by using electronic signatures which are suppor
21、ted by a certification-service-provider issuing certificates, commonly called a certification authority. The Directive 1999/93/EC of the European Parliament and of the Council on a Community framework for electronic signatures 1 (hereinafter referred to as “the Directive“) identifies a special form
22、of electronic signature which is based on a “qualified certificate“. Annex I of this Directive specifies requirements for qualified certificates. Annex II of the Directive specifies requirements on certification-service-providers issuing qualified certificates (i.e. certification authorities issuing
23、 qualified certificates). Annex III specifies requirements for secure signature creation devices. For users of electronic signatures to have confidence in the authenticity of the qualified electronic signatures they need to have confidence that the CA that issued the qualified certificate the electr
24、onic signature is based upon has properly established procedures and protective measure in order to minimize the operational and financial threats and risks associated with public key crypto systems. ETSI ESI issued, and keeps updated, the Technical Specification TS 101 456 15 that specifies baselin
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITR1024372006ELECTRONICSIGNATURESANDINFRASTRUCTURESESIGUIDANCEONTS101456POLICYREQUIREMENTSFORCERTIFICATIONAUTHORITIESISSUINGQUALIFIEDCERTIFICATESV11PDF

链接地址:http://www.mydoc123.com/p-735922.html