- Supports public documentation availability, sensitive-information limits, audit logging, records retention, and continuity obligations for trust service providers.
"make available to subscribers and relying parties"
A focused guide to how ETSI EN 319 411-1 handles subscriber and subject identity before certificate issuance.
Use it to check registration evidence, certificate request approval, RA responsibilities, and records without exposing internal source records.
Structured answer sets in this page tree.
Cited legal and guidance references.
ETSI EN 319 411-1 requires the TSP to verify the subscriber and , collect and validate direct evidence or an attestation from an appropriate authorized source for the subject's identity and attributes, and check each certificate request against that evidence. The exact route depends on the policy profile, subject type, subscriber-subject relationship, and any live CA/Browser Forum rules for web certificates. This page applies V1.5.1 (April 2025). Its EN 319 401 reference is non-specific, so clause 2.1 makes the latest edition applicable; record the EN 319 401 edition and assessment date used.
The standard separates certification services into registration, certificate generation, dissemination, revocation management, revocation status, and optional device provision. Identity validation belongs first in registration, but EN 319 411-1 also states that it can be part of certificate application, certificate issuance, or subject device provisioning.
The CP and CPS should keep that boundary clear. The certificate policy identifies the policy rules and certificate profile expectations; the certification practice statement explains how the TSP operates the process. NCP+ and EVCP inherit NCP requirements unless stated otherwise, while DVCP, OVCP, and IVCP inherit LCP requirements. The CPS and supporting records should trace each request to the applicable route, registration evidence, approvals, RA action, and certificate profile.
Clause 6.2.2 starts with the same baseline for every route: the TSP verifies the identity of the subscriber and , collects and validates direct evidence or an attestation from an appropriate authorized source for the subject's identity and attributes, and checks that certificate requests are accurate, authorized, and complete against that evidence.
The details then depend on who or what the certificate identifies. A natural-person needs identity attributes that distinguish the person. A natural person acting with a legal person needs personal identity, organization identity, affiliation, and approvals. A legal-person subject needs organizational identity evidence. A device or system subject needs the device identifier plus the operator's identity and authorization context.
Registration evidence is not enough by itself. Before issuing, renewing, re-keying, or modifying a certificate, EN 319 411-1 requires the subscriber to have been registered and the subscriber and identity to have been validated. The TSP also has to assess that the subject attributes and other certificate information are correct at issuance time.
The CP/CPS must define how long a certificate may be issued after initial identity validation without repeating validation, and how often or under what conditions prior validation can be reused. If the process used for the original identity proofing is no longer acceptable under the CPS because of security concerns, it must not be relied on for issuance.
This ETSI EN 319 411-1 guide helps align registration evidence, subscriber authority, RA actions, issuance checks, and public disclosure language.
Convert identity validation clauses into accountable evidence requests, registration checks, and certificate issuance gates.
Resolve subscriber, subject, RA, evidence, and CP/CPS questions against cited ETSI source material.
Review the certificate types, validation routes, records, and public disclosures that matter for your certificate service.
The identity validation record should show what was checked, which source or attestation supported it, who approved it, and which certificate request relied on it. EN 319 411-1 does not require every collected document to be archived long term; it allows a record to refer to the documentation used at the time, while still requiring the information necessary to verify identity and attributes, including document reference numbers and limitations on validity.
Public-facing disclosures should not expose sensitive registration data. The standard requires the CPS to be publicly available online, but notes that sensitive aspects do not have to be disclosed. Clause 6.4.6 sets a seven-year minimum after the affected certificate ceases to be valid for CA-managed key-lifecycle logs and the subscriber documentation identified in clause 6.3.4; it does not require every identity document collected during registration to be retained for that period. Other record periods follow the applicable requirement, disclosed practices, and terms.
"make available to subscribers and relying parties"
"record all the information necessary"
"trust services"