5.4.1 已翻譯 對應原文版本:2.3.0

應記錄之事件類型

跳至原文

Types of events recorded

The CA and each Delegated Third Party SHALL record events related to the security of their Certificate Systems, Certificate Management Systems, Root CA Systems, and Delegated Third Party Systems. The CA and each Delegated Third Party SHALL record events related to their actions taken to process a certificate request and to issue a Certificate, including all information generated and documentation received in connection with the certificate request; the time and date; and the personnel involved. The CA SHALL make these records available to its Qualified Auditor as proof of the CA’s compliance with these Requirements.

憑證機構(Certification Authority,CA)及每個受委任第三方(Delegated Third Party)應(SHALL)記錄其憑證系統(Certificate System)、憑證管理系統(Certificate Management System)、根憑證機構系統(Root CA System)及受委任第三方系統(Delegated Third Party Systems)之安全有關的事件。CA 及每個受委任第三方應(SHALL)記錄其處理憑證申請及簽發憑證所採取之措施,包括與該憑證申請相關而產生之所有資訊、所接收之文件、處理之時間與日期,以及參與之人員。CA 應(SHALL)提供此類紀錄供其合格稽核業者(Qualified Auditor)查核,作為 CA 遵循本文件要求規定之證明。

The CA SHALL record at least the following events:

CA 應(SHALL)至少記錄下列事件:

  1. CA certificate and key lifecycle events, including:

    1. Key generation, backup, storage, recovery, archival, and destruction;
    2. Certificate requests, renewal, and re-key requests, and revocation;
    3. Approval and rejection of certificate requests;
    4. Cryptographic device lifecycle management events;
    5. Generation of Certificate Revocation Lists;
    6. Signing of OCSP Responses (as described in Section 4.9 and Section 4.10); and
    7. Introduction of new Certificate Profiles and retirement of existing Certificate Profiles.
  1. CA 憑證及金鑰生命週期事件,包括:

    1. 金鑰之產生、備份、儲存、復原、封存及銷毀;

    2. 憑證申請、憑證展期與金鑰更換請求,以及廢止;

    3. 憑證申請之核准與拒絕;

    4. 密碼學裝置(Cryptographic Device)生命週期管理事件;

    5. 憑證廢止清冊(Certificate Revocation List,CRL)之產生;

    6. OCSP 回應之簽章(如第 4.9 節及第 4.10 節所述);以及

    7. 新增憑證剖繪(Certificate Profiles)及現有憑證剖繪之退役。

  1. Subscriber Certificate lifecycle management events, including:

    1. Certificate requests, renewal, and re-key requests, and revocation;
    2. All verification activities stipulated in these Requirements and the CA’s Certification Practice Statement. Effective 2026-07-15, records MUST include at a minimum:
      1. the information being validated (e.g., the applied-for FQDN or the organization name);
      2. the ADN used (if applicable and different from the applied-for FQDN); and
      3. the validation method used (e.g., the BRs section number or the registered label of an ACME validation method);
    3. Approval and rejection of certificate requests;
    4. Issuance of Certificates;
    5. Generation of Certificate Revocation Lists; and
    6. Signing of OCSP Responses (as described in Section 4.9 and Section 4.10).
    7. Multi-Perspective Issuance Corroboration attempts from each Network Perspective, minimally recording the following information:
      1. an identifier that uniquely identifies the Network Perspective used;
      2. the attempted domain name and/or IP address; and
      3. the result of the attempt (e.g., “domain validation pass/fail”, “CAA permission/prohibition”).
    8. Multi-Perspective Issuance Corroboration quorum results for each attempted domain name or IP address represented in a Certificate request (i.e., “3/4” which should be interpreted as “Three (3) out of four (4) attempted Network Perspectives corroborated the determinations made by the Primary Network Perspective).
  1. 用戶憑證(Subscriber Certificate)生命週期管理事件,包括:

    1. 憑證申請、憑證展期與金鑰更換請求,以及廢止;

    2. 本文件及 CA 憑證實務作業基準(Certification Practice Statement,CPS)所規定之所有驗證活動。自 2026-07-15 起,紀錄應(MUST)至少包含:

      1. 受驗證之資訊(例如所申請的完全吻合網域名稱(FQDN)或組織名稱);
      2. 所使用之經授權網域名稱(ADN)(若適用,且所使用之經授權網域名稱(ADN)與所申請的 FQDN 不相同);以及
      3. 所使用之驗證方法(例如《基本要求》的章節編號或 ACME 驗證方法於 IANA 登記之名稱(registered label));
    3. 憑證申請之核准與拒絕;

    4. 憑證之簽發;

    5. 憑證廢止清冊(CRL)之產生;以及

    6. OCSP 回應之簽章(如第 4.9 節及第 4.10 節所述)。

    7. 每個網路視角(Network Perspective)執行多視角簽發佐證(Multi-Perspective Issuance Corroboration)時,至少應記錄下列資訊:

      1. 用以識別所使用之網路視角的唯一識別碼;
      2. 進行驗證之網域名稱及/或 IP 位址;以及
      3. 該次執行之結果(例如「網域驗證通過/失敗」、「CAA 許可/禁止」)。
    8. 憑證申請所包含之每個網域名稱或 IP 位址的多視角簽發佐證法定數量(Quorum)結果(例如「3/4」,表示 4 個網路視角中,有 3 個佐證了主要網路視角(Primary Network Perspective)所做之判定」)。

  1. Security events, including:

    1. Successful and unsuccessful PKI system access attempts;
    2. PKI and security system actions performed;
    3. Security profile changes;
    4. Installation, update and removal of software on a Certificate System;
    5. System crashes, hardware failures, and other anomalies;
    6. Relevant router and firewall activities (as described in Section 5.4.1.1); and
    7. Entries to and exits from the CA facility.
  1. 安全事件,包括:

    1. PKI(公開金鑰基礎建設)系統存取成功及失敗之結果;

    2. PKI 及安全系統所執行之操作;

    3. 安全剖繪(Security profile)變更;

    4. 憑證系統(Certificate System)上之軟體安裝、更新及移除;

    5. 系統當機、硬體故障及其他異常;

    6. 相關路由器及防火牆活動(如第 5.4.1.1 節所述);以及

    7. 進出 CA 設施之記錄。

Log records MUST include at least the following elements:

  1. Date and time of event;
  2. Identity of the person making the journal record (when applicable); and
  3. Description of the event.

紀錄內容應(MUST)至少包含下列要素:

  1. 事件發生日期與時間;

  2. 建立該事件紀錄之人員識別資訊(若適用);以及

  3. 事件內容描述。