跳到主要内容

2.24. 新增 Section 8.6 - 使用 CMP Message 进行 Trust Anchor Provisioning

2.24. 新增 Section 8.6 - 使用 CMP Message 进行 Trust Anchor Provisioning

以下小节讨论在 PKI management operation 中 in-band provisioning 新 trust anchor 所带来的风险.

在新的 Section 8.5 之后插入本节:

8.6. 使用 CMP Message 进行 Trust Anchor Provisioning

trust anchor provider, 可能是参与其 client 配置管理的 RA, MUST NOT 在 CMP message 中包含待信任的 CA certificate, 除非具体 deployment scenario 能够确保 receiving EE 信任这些 certificate 是适当的, 例如将它们加载到其 trust store 中.

每当 EE 在 CMP message 中收到将用作 trust anchor 的 CA certificate (例如在 certificate response 的 caPubs 字段中或在 general response 中), 它 MUST 使用现有 trust anchor information 正确认证 message sender, 且不得依赖 message 中包含的新 trust anchor.

此外, EE MUST 验证 sender 是 trust anchor 的 authorized source. 此授权由 local policy 管理, 通常通过 shared secret information 指示, 或通过 signature-based message protection 指示, 后者使用由明确授权用于此目的的 PKI 签发的 certificate.