What must be validated before a certificate is issued?
Clause 6.2.2 starts with a direct rule: the TSP verifies the identity of the and the . It then requires the TSP to collect and validate either direct evidence or an attestation from an appropriate and authorized source for the subject's identity and, where applicable, subject attributes.
The validation decision must also cover the certificate request itself. ETSI EN 319 411-1 requires the TSP to check that certificate requests are accurate, authorized, and complete against the collected evidence or attestation. Identity verification happens at registration, but issuance may occur later. At issuance, the attributes must still be correct, the original proofing process must remain acceptable under the CPS, and the CP/CPS must define how long and how often identity validation may be reused without a new validation.
- Identify whether the subject is a natural person, a natural person linked to a legal person, a legal person or organizational entity, or a device or system operated by or for a natural or legal person.
- Collect direct evidence or an authorized-source attestation for the subject identity and any certificate attributes that will be included or relied on.
- Check request accuracy, authorization, and completeness before certificate generation uses the registration result.
- Record the age of reused evidence and the CP/CPS reuse rule; refresh identity validation when the allowed time, frequency, security, or change conditions are not met.
Primary source for clause 6.2.2 initial identity validation: subscriber and subject verification, evidence or attestation, registration timing, and request accuracy checks.
Supports the records governance behind identity-validation evidence, including accessible records, integrity, confidentiality, and legal-evidence purposes.