How should certificate authorities handle re-key under ETSI EN 319 411-1?
Treat re-key as a certificate lifecycle event that starts with a new subject public key. A instead keeps the previously certified public key and is allowed only when that key remains cryptographically sufficient for the new validity period and there is no indication of compromise or revocation for another security breach. ETSI EN 319 411-1 clause 6.3.7 says the general certificate application and application-processing requirements in clauses 6.3.1 and 6.3.2 still apply to re-key. The request must remain linked to registration, authorization, current identity or attribute evidence, and the public key being certified. If the CA did not generate the new key pair, the request process must provide reasonable assurance that the subject possesses or controls the corresponding private key.
The CP/CPS should be the operating boundary. It needs to state whether, and under which circumstances, the TSP allows to change the expiry date or certified attributes. If the previous certificate is used to authenticate the re-key request, the TSP checks that the previous certificate exists and is valid.
- Confirm the event is re-key, not renewal: the subject public key changes.
- Apply the certificate application and processing controls from clauses 6.3.1 and 6.3.2 to the re-key request.
- Verify and record changed certified names or attributes before including them in the replacement certificate.
- Check the existing certificate when it is used to authenticate the request.
- Communicate and obtain agreement to changed terms and conditions before completing the re-key.
- Decide separately whether an unexpired earlier certificate remains valid or must be revoked; issuing the re-keyed certificate does not automatically change the earlier certificate's status.
Defines certificate re-key as issuance with a new subject public key and lists the clause 6.3.7 controls for attributes, expiry changes, previous-certificate authentication, and changed terms.
Provides the general trust service provider policy framework referenced by ETSI EN 319 411-1 for governance, practice statements, security, and auditability.