| Scope and certificate types | EN 319 411-1 covers TSPs issuing public key certificates, including trusted web site certificates, and supports reference policies such as LCP, NCP, NCP+, DVCP, OVCP, IVCP, and EVCP. | A policy that only adopts [WEB]-tagged controls follows selected requirements from BR V1.8.6. A CA asserting DVCP, OVCP, or IVCP follows the full latest BR for the corresponding publicly trusted TLS certificate policy. | Name the certificate policy and OID first. That determines whether the ETSI bridge is limited to selected [WEB] controls or extends to the full latest BR. |
|---|
| Covered actors | EN 319 411-1 applies to TSPs issuing public key certificates and covers the CA, registration, dissemination, revocation management, revocation status, and optional subject-device functions within their certificate services. | The BRG dependency arises for TSPs asserting DVCP, OVCP, or IVCP policy OIDs for publicly trusted TLS/SSL certificates, where root programs, browser vendors, and relying parties depend on CA/Browser Forum requirements being satisfied. | Map actors by their certificate-service role under EN 319 411-1 and by their CA, delegated-party, application-software-supplier, or relying-party role under the BR. |
|---|
| Trigger | An EN 319 411-1 review is triggered when a certification authority asserts an ETSI NCP, LCP, NCP+, DVCP, OVCP, IVCP, or EVCP certificate policy OID, or when a CP/CPS review or audit is required for any of those policy profiles. | A full current BR review is required by the ETSI policy definition when a CA asserts DVCP, OVCP, or IVCP. A policy that uses [WEB]-tagged controls without one of those profiles follows the selected BR V1.8.6 references, not automatically the full latest BR. | Record the exact policy profile and whether the dependency arises from a [WEB] tag, a DVCP/OVCP/IVCP OID, or a separate relying-party or contractual rule. |
|---|
| Core obligations | EN 319 411-1 requires a CP stating what must be adhered to and a CPS explaining how the TSP implements those requirements. Selected obligations are tagged [WEB] to mark controls that apply specifically to web-authentication certificates; DVCP, OVCP, and IVCP profiles add BRG-linked CPS duties. | Selected BR V1.8.6 requirements are incorporated for [WEB] controls, including domain and IP address validation. DVCP, OVCP, and IVCP add full-current-BR monitoring and a conditional conflict rule: the latest BR prevails unless EN 319 411-1 is more stringent. | Keep the fixed-version [WEB] mapping separate from the full-current-BR mapping for DVCP, OVCP, and IVCP. |
|---|
| Evidence | EN 319 411-1 requires the TSP to verify subscriber and subject identity, check requests for accuracy, authorization, and completeness, and collect or validate direct evidence or attestation from appropriate sources. | For [WEB] information relating to domain names and IP addresses, REG-6.2.2-03A points to BR V1.8.6 clauses 3.2.2.4 through 3.2.2.9. A DVCP, OVCP, or IVCP review must also account for the current BR, whose numbering and effective requirements can differ. | Record the validation method, the ETSI requirement, the fixed BR clause cited by ETSI, and the corresponding current BR requirement when the full-BR policy route applies. |
|---|
| Timing | EN 319 411-1 requires public CPS disclosure, availability of terms and conditions to relying parties, public international availability of those terms for publicly trusted certificates, support for OCSP or CRL, and public international availability of revocation status information. | The current BR has its own effective dates and lifecycle deadlines. Those requirements must be read from the live BR for DVCP, OVCP, and IVCP rather than inferred from ETSI notes or older clause references. | Track ETSI availability duties and current BR deadlines as separate cited controls; apply the stricter rule where the ETSI conflict clause requires it. |
|---|
| Conflict and change control | EN 319 411-1 V1.5.1 sets the ETSI baseline and permits confidential CPS sections. ETSI TC ESI is the relevant body for EN 319 411-1 revisions; conflicts with CA/B Forum SSL/TLS certificate policies should be reported to both ETSI TC ESI and the CA/Browser Forum. | For OVCP, DVCP, and IVCP, BRG takes precedence when EN 319 411-1 conflicts with the latest BRG version, unless EN 319 411-1 is more stringent. The TSP must monitor BRG revisions and ensure compliance as requirements become effective, making BRG monitoring a live, repeating obligation. | When BRG conflicts with EN 319 411-1 for DVCP, OVCP, or IVCP, BRG takes precedence unless the ETSI requirement is more stringent; retain the conflict and stringency analysis. |
|---|
| Overlap | EN 319 411-1 supplies the TSP baseline for registration, publication, certificate generation, revocation management, and certificate status services. | The BR can address the same operations for publicly trusted TLS certificates, but the actors, conditions, deadlines, and evidence details must be compared requirement by requirement. | A shared artifact may support both sources, but do not label a control jointly satisfied until the applicable ETSI and current BR requirements have been compared and the service boundary matches. |
|---|
| Decision rule | ETSI evidence should be organized by policy profile and service component: CP/CPS, subscriber and subject registration, certificate generation, dissemination, revocation management, revocation status, and supporting procedures. | Keep a fixed-version mapping for selected [WEB] controls and a current-version mapping for DVCP, OVCP, or IVCP. Add any separate application-software supplier or root-program requirements as their own source layer. | Do not infer public trust from an ETSI assessment. Public trust depends on the root being distributed by application software and on the applicable relying-party program requirements. |
|---|