6.1.1.1 已翻譯 對應原文版本:2.3.0

憑證機構(CA)金鑰對之產製

跳至原文

CA Key Pair Generation

For CA Key Pairs that are either:

  1. used as a CA Key Pair for a Root Certificate or
  2. used as a CA Key Pair for a Subordinate CA Certificate, where the Subordinate CA is not the operator of the Root CA or an Affiliate of the Root CA,

對於符合下列任一情形之憑證機構(CA)金鑰對:

  1. 作為根憑證(Root Certificate)之 CA 金鑰對使用;或
  2. 作為下屬憑證機構憑證(Subordinate CA Certificate)之 CA 金鑰對使用,且該下屬憑證機構(Subordinate CA)並非根憑證機構(Root CA)之營運者,亦非根憑證機構之關係企業(Affiliate),

the CA SHALL:

憑證機構(Certification Authority,CA)應(SHALL):

  1. prepare and follow a Key Generation Script,
  1. 準備並遵從金鑰產製腳本(Key Generation Script),
  1. have a Qualified Auditor witness the CA Key Pair generation process or record a video of the entire CA Key Pair generation process, and
  1. 由合格稽核業者(Qualified Auditor)見證 CA 金鑰對之產製流程,或錄製整個 CA 金鑰對產製流程之影片,以及
  1. have a Qualified Auditor issue a report opining that the CA followed its key ceremony during its Key and Certificate generation process and the controls used to ensure the integrity and confidentiality of the Key Pair.
  1. 由合格稽核業者出具報告,就下列事項表示意見:CA 於其金鑰及憑證產製流程中已遵從其金鑰儀式(Key Ceremony),以及用於確保該金鑰對完整性與機密性之控管措施已妥善實施。

For other CA Key Pairs that are for the operator of the Root CA or an Affiliate of the Root CA, the CA SHOULD:

對於供根憑證機構(Root CA)營運者或根憑證機構關係企業使用之其他 CA 金鑰對,憑證機構(CA)宜(SHOULD):

  1. prepare and follow a Key Generation Script and
  1. 準備並遵從金鑰產製腳本,以及
  1. have a Qualified Auditor witness the CA Key Pair generation process or record a video of the entire CA Key Pair generation process.
  1. 由合格稽核業者見證 CA 金鑰對之產製流程,或錄製整個 CA 金鑰對產製流程之影片。

In all cases, the CA SHALL:

在所有情況下,憑證機構(CA)應(SHALL):

  1. generate the CA Key Pair in a physically secured environment as described in the CA’s Certificate Policy and/or Certification Practice Statement;
  1. 依據 CA 的憑證政策(Certificate Policy,CP)及/或憑證實務作業基準(Certification Practice Statement,CPS)所述,於實體安全環境中產製 CA 金鑰對;
  1. generate the CA Key Pair using personnel in Trusted Roles under the principles of multiple person control and split knowledge;
  1. 由擔任信賴角色(Trusted Role)之人員,依循多人控管(multiple person control)及分拆知識(split knowledge)原則產製 CA 金鑰對;
  1. generate the CA Key Pair within cryptographic modules meeting the applicable technical and business requirements as disclosed in the CA’s Certificate Policy and/or Certification Practice Statement;
  1. 於符合 CA 憑證政策(CP)及/或憑證實務作業基準(CPS)所載之適用技術及業務要求規定的密碼模組(cryptographic module)內產製 CA 金鑰對;
  1. log its CA Key Pair generation activities; and
  1. 記錄其 CA 金鑰對產製活動;以及
  1. maintain effective controls to provide reasonable assurance that the Private Key was generated and protected in conformance with the procedures described in its Certificate Policy and/or Certification Practice Statement and (if applicable) its Key Generation Script.
  1. 維持有效的控管措施,以便合理確信私密金鑰係依其憑證政策(CP)及/或憑證實務作業基準(CPS)所述之程序,以及(若適用)其金鑰產製腳本產製而成並受到保護。