What should a CA document before enabling suspension?
Treat suspension as part of the same controlled certificate-status process as revocation, while keeping the two outcomes distinct. A cannot be reinstated under EN 319 411-1; suspension is useful only where the applicable certificate policy, CPS, customer terms, and status systems can represent a temporary invalid state without confusing relying parties.
The CPS must describe whether and for what reasons certificates can be suspended or revoked, who may submit requests or event reports, the request and confirmation process, the status-distribution mechanism, and the maximum delays. EN 319 411-1 sets an outer timing rule: changed status information must be available to all relying parties within 24 hours after receipt of a revocation or suspension request. If a request schedules suspension for a future date, that date may count as the receipt time.
- Define the suspension model in the CPS: supported certificate policies, accepted requesters, permitted reasons, confirmation method, status-service method, and how suspension differs from final revocation.
- Process requests and event reports on receipt, authenticate them, and check that they come from an authorized source before changing status.
- Make the suspension status visible through the CA's revocation-status service, such as CRL or OCSP, within the documented delay and no later than the ETSI 24-hour maximum after request receipt.
- Inform the subject and, where applicable, the subscriber of a suspended certificate when this is possible.
- Do not describe a suspended certificate as valid during the suspension period; relying-party notices should direct users to current certificate-status information.
Supports the suspension handling answer through clause 6.2.4 disclosure and timing requirements, clause 6.3.9 revocation and suspension requirements, and clause 6.3.10 certificate status service requirements.
Supports the general TSP management-system context for controlled procedures, evidence, security management, and continuity behind certificate-status operations.