6.2.7 已翻譯 對應原文版本:2.3.0
私密金鑰儲存於密碼模組
Private key storage on cryptographic module
The CA SHALL protect its Private Key in a system or device that has been validated as meeting at least FIPS 140-2 level 3, FIPS 140-3 level 3, or an appropriate Common Criteria Protection Profile or Security Target, EAL 4 (or higher), which includes requirements to protect the Private Key and other assets against known threats.
憑證機構(Certification Authority,CA)應(SHALL)於經驗證至少符合下列任一標準之系統或裝置中保護其私密金鑰:FIPS 140-2 Level 3、FIPS 140-3 Level 3,或達到 EAL 4(或更高等級)之適當 Common Criteria Protection Profile 或 Security Target 標準,上述標準應包含保護私密金鑰及其他資產免於已知威脅之要求。