私密金鑰保護及密碼模組工程控管
Private Key Protection and Cryptographic Module Engineering Controls
The CA SHALL implement physical and logical safeguards to prevent unauthorized certificate issuance. Protection of the CA Private Key outside the validated system or device specified in Section 6.2.7 MUST consist of physical security, encryption, or a combination of both, implemented in a manner that prevents disclosure of the Private Key. The CA SHALL encrypt its Private Key with an algorithm and key-length that, according to the state of the art, are capable of withstanding cryptanalytic attacks for the residual life of the encrypted key or key part.
憑證機構(Certification Authority,CA)應(SHALL)實施實體及邏輯保護措施,以防止未經授權之憑證簽發。位於第 6.2.7 節指定之已驗證系統或裝置以外的 CA 私密金鑰,其保護措施應(MUST)採用實體安全、加密,或兩者之組合,且其實施方式須能防止私密金鑰遭揭露。CA 應(SHALL)使用依據當前技術水準,足以在加密金鑰或金鑰部分之剩餘有效期內抵抗密碼分析攻擊的演算法及金鑰長度,加密其私密金鑰。