6.1.1.1 已翻譯 對應原文版本:2.3.0
憑證機構(CA)金鑰對之產製
CA Key Pair Generation
For CA Key Pairs that are either:
- used as a CA Key Pair for a Root Certificate or
- used as a CA Key Pair for a Subordinate CA Certificate, where the Subordinate CA is not the operator of the Root CA or an Affiliate of the Root CA,
對於符合下列任一情形之憑證機構(CA)金鑰對:
- 作為根憑證(Root Certificate)之 CA 金鑰對使用;或
- 作為下屬憑證機構憑證(Subordinate CA Certificate)之 CA 金鑰對使用,且該下屬憑證機構(Subordinate CA)並非根憑證機構(Root CA)之營運者,亦非根憑證機構之關係企業(Affiliate),
the CA SHALL:
憑證機構(Certification Authority,CA)應(SHALL):
- prepare and follow a Key Generation Script,
- 準備並遵從金鑰產製腳本(Key Generation Script),
- have a Qualified Auditor witness the CA Key Pair generation process or record a video of the entire CA Key Pair generation process, and
- 由合格稽核業者(Qualified Auditor)見證 CA 金鑰對之產製流程,或錄製整個 CA 金鑰對產製流程之影片,以及
- have a Qualified Auditor issue a report opining that the CA followed its key ceremony during its Key and Certificate generation process and the controls used to ensure the integrity and confidentiality of the Key Pair.
- 由合格稽核業者出具報告,就下列事項表示意見:CA 於其金鑰及憑證產製流程中已遵從其金鑰儀式(Key Ceremony),以及用於確保該金鑰對完整性與機密性之控管措施已妥善實施。
For other CA Key Pairs that are for the operator of the Root CA or an Affiliate of the Root CA, the CA SHOULD:
對於供根憑證機構(Root CA)營運者或根憑證機構關係企業使用之其他 CA 金鑰對,憑證機構(CA)宜(SHOULD):
- prepare and follow a Key Generation Script and
- 準備並遵從金鑰產製腳本,以及
- have a Qualified Auditor witness the CA Key Pair generation process or record a video of the entire CA Key Pair generation process.
- 由合格稽核業者見證 CA 金鑰對之產製流程,或錄製整個 CA 金鑰對產製流程之影片。
In all cases, the CA SHALL:
在所有情況下,憑證機構(CA)應(SHALL):
- generate the CA Key Pair in a physically secured environment as described in the CA’s Certificate Policy and/or Certification Practice Statement;
- 依據 CA 的憑證政策(Certificate Policy,CP)及/或憑證實務作業基準(Certification Practice Statement,CPS)所述,於實體安全環境中產製 CA 金鑰對;
- generate the CA Key Pair using personnel in Trusted Roles under the principles of multiple person control and split knowledge;
- 由擔任信賴角色(Trusted Role)之人員,依循多人控管(multiple person control)及分拆知識(split knowledge)原則產製 CA 金鑰對;
- generate the CA Key Pair within cryptographic modules meeting the applicable technical and business requirements as disclosed in the CA’s Certificate Policy and/or Certification Practice Statement;
- 於符合 CA 憑證政策(CP)及/或憑證實務作業基準(CPS)所載之適用技術及業務要求規定的密碼模組(cryptographic module)內產製 CA 金鑰對;
- log its CA Key Pair generation activities; and
- 記錄其 CA 金鑰對產製活動;以及
- maintain effective controls to provide reasonable assurance that the Private Key was generated and protected in conformance with the procedures described in its Certificate Policy and/or Certification Practice Statement and (if applicable) its Key Generation Script.
- 維持有效的控管措施,以便合理確信私密金鑰係依其憑證政策(CP)及/或憑證實務作業基準(CPS)所述之程序,以及(若適用)其金鑰產製腳本產製而成並受到保護。