-
Notifications
You must be signed in to change notification settings - Fork 105
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Replace PKI system with Certificate Management System in 5.4.1 #329
base: main
Are you sure you want to change the base?
Conversation
Hi All,
|
I definitely agree that we should be cleaning up terminology to improve clarity, and replacing "PKI system" with Defined Terms is a good step in that direction. I'm not sure that replacing "PKI system" with "Certificate Management System" is sufficient, as the definition of "Certificate Management System" appears to be limited to those systems that are not directly involved in signing operations. To ensure that we include those Certificate issuance systems in requirement, I suggest we use the Defined Term "Certificate System" instead or use the NSR convention of explicitly listing out potentially redundant items such as "Certificate Systems, Issuing Systems, Certificate Management Systems, Security Support Systems, and Front-End / Internal-Support Systems". More generally (not something that needs to be tackled in this ballot), but we should add a note to section 1.6.1 to denote that all definitions in the NSRs are included in the BRs, as they are used throughout the BRs (not just in section 5). For example, the NSR Defined Term "Trusted Role" is used in section 6. |
fwiw, I have this in my SC51 draft |
Agreeing to what Corey mentioned in the previous comment, I made the changes to the requirement to explicitly say 'Certificate Systems, Issuing Systems, Certificate Management Systems, Security Support Systems, and Front-End / Internal-Support Systems'. This aligns well with the current NSR conventions. |
Looking for further feedback on this change 🙂 Once the new Netsec WG adopts the NSRs, I would really appreciate if someone can shepherd this change via a ballot. Thanks !! |
No description provided.