Can a certificate authority delegate RA work under ETSI EN 319 411-1?
Yes, but delegation does not turn registration into an unmanaged hand-off. ETSI EN 319 411-1 defines a Registration Authority as the entity responsible mainly for identifying and authenticating certificate subjects, and notes that an RA can assist with certificate applications, revocation, or both.
For initial identity validation, the TSP must ensure that the subscriber and subject are verified, that direct evidence or an attestation from an appropriate and authorized source is collected and validated, and that certificate requests are accurate, authorized, and complete. A subcontracted person may supply identity evidence only when the identity check follows clause 6.2.2. The registration officer who verifies identity cannot be the natural person receiving the certificate.
- Define which RA tasks are delegated: identity proofing, certificate application intake, revocation request handling, or registration-data submission.
- Keep the TSP accountable for the certificate policy and CPS controls even when the registration work is performed by another party.
- Do not accept delegated registration evidence unless it supports the subject, subscriber, authorization, and certificate profile requirements that apply to the certificate being issued.
- Keep certificate issuance separate from registration approval: the application must come from a trusted and authorized source, and the issuing procedure must remain securely and unambiguously linked to the associated registration.
Defines Registration Authority responsibilities and supports the answer that delegated identity evidence must still satisfy clause 6.2.2 validation requirements.
Supports the point that subcontracting or outsourcing does not remove the TSP's overall responsibility for policy conformance.