18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

REMOTE DATA ENTRY<br />

Auditable Event CA CSA RA<br />

All security-relevant messages that are received by the<br />

system<br />

DATA EXPORT AND OUTPUT<br />

All successful and unsuccessful requests for confidential and<br />

security-relevant information<br />

KEY GENERATION<br />

Whenever the component generates a key (not mandatory for<br />

single session or one-time use symmetric keys)<br />

PRIVATE KEY LOAD AND STORAGE<br />

X X X<br />

X X X<br />

X X X<br />

The loading of component private keys X X X<br />

All access to certificate subject Private <strong>Key</strong>s retained within<br />

the CA for key recovery purposes<br />

TRUSTED PUBLIC KEY ENTRY, DELETION AND STORAGE<br />

All changes to the trusted component <strong>Public</strong> <strong>Key</strong>s, including<br />

additions and deletions<br />

SECRET KEY STORAGE<br />

X N/A N/A<br />

X X X<br />

The manual entry of secret keys used for authentication X X X<br />

PRIVATE AND SECRET KEY EXPORT<br />

The export of private and secret keys (keys used for a single<br />

session or message are excluded)<br />

CERTIFICATE REGISTRATION<br />

X X X<br />

All certificate requests X N/A X<br />

CERTIFICATE REVOCATION<br />

All certificate revocation requests X N/A X<br />

CERTIFICATE STATUS CHANGE APPROVAL<br />

The approval or rejection of a certificate status change<br />

request<br />

CA CONFIGURATION<br />

Any security-relevant changes to the configuration of the<br />

component<br />

ACCOUNT ADMINISTRATION<br />

X N/A N/A<br />

X X X<br />

Roles and users are added or deleted X - -<br />

The access control privileges of a user account or a role are<br />

modified<br />

CERTIFICATE PROFILE MANAGEMENT<br />

X - -<br />

All changes to the certificate profile X N/A N/A<br />

CERTIFICATE STATUS AUTHORITY MANAGEMENT<br />

All changes to the CSA profile (e.g. OCSP profile) N/A X N/A<br />

50 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!