- Current general TSP requirements supporting the practice-statement, evidence, logging, and operational context used by EN 319 411-1.
"General Policy Requirements for Trust Service Providers"
A workflow for proving how a trust service provider receives, authenticates, decides, publishes, and records certificate revocation events.
Based on ETSI EN 319 411-1 V1.5.1 clauses for CPS revocation procedures, certificate status services, CRL/OCSP publication, audit logging, and records archival.
Structured answer sets in this page tree.
Cited legal and guidance references.
Process an authorized request or event report when it arrives. When the decision changes certificate status, do not close the case until the changed status is available to relying parties through every supported method. This workflow applies ETSI EN 319 411-1 V1.5.1 (2025-04) to CPS procedures, request authentication, decisions, CRL or OCSP publication, exceptions, audit logs, and records. Short-term and validity-assured certificates need the separate branches below.
The first evidence item is the (CPS) section for of end-user and CA certificates. It should identify who can submit a revocation request or report a revocation event, how the request is submitted, when confirmation is required, the reasons a certificate can be suspended or revoked, the status-distribution mechanism, and the maximum publication delays.
Treat that CPS section as the control map for operations. Each intake channel, authorization rule, confirmation step, suspension reason, reason, CRL location, OCSP endpoint, and relying-party disclosure should be traceable to a clause, an owner, and a record.
The operational workflow should begin when a request or report is received, not when a weekly review queue is opened. EN 319 411-1 says requests and event reports are processed on receipt and authenticated as coming from an authorized source.
The workflow also needs time evidence. The time used for services must be synchronized with UTC at least once every 24 hours. The maximum delay from receipt of a revocation or suspension request to the actual status change being available to all relying parties is 24 hours; for a future-dated request, the scheduled date may count as receipt. If confirmation cannot be completed within 24 hours, follow the CPS exception procedure and record the actions and justification.
The evidence trail is incomplete until relying parties can check certificate status, unless a defined exception applies. EN 319 411-1 requires OCSP or CRL, 24-hour-per-day and 7-day-per-week availability, integrity and authenticity protection, coverage at least until certificate expiry, and public international availability. A TSP need not provide status services for a certificate containing the validity assured extension.
If the service uses a (CRL), prove the publication schedule, nextUpdate handling, signing authority, and any last-CRL condition. If the service uses the (OCSP), prove responder profile handling and that a non-issued certificate is not returned as good. If both CRL and OCSP are supported, updates must be available through both methods and the CPS must explain the source and interpretation of possible temporary differences.
This table is the operating workflow for each case or periodic audit sample: Step | Owner | Evidence | Acceptance test.
1 | CPS owner | CPS procedure, certificate policy mapping, subscriber and relying-party disclosures | The CPS identifies submitters, submission methods, confirmation rules, revocation and suspension reasons, status mechanisms, and maximum delays.
2 | officer or authorized operations role | Request record, event report, submitter authentication, certificate serial number, reason, receipt timestamp | The request was processed on receipt and authenticated as coming from an authorized source.
3 | CA or management service | Decision record, approval trail, confirmation result, exception justification if needed | The actual change of certificate status information is available to all relying parties within 24 hours after receipt of the request; if confirmation was not completed within 24 hours, the CPS exception procedure, actions, and justification are recorded.
4 | Repository, CRL, or OCSP owner | CRL publication log, OCSP response evidence, endpoint monitoring, signer controls | Relying parties can obtain protected status information through the required method.
5 | Audit and records owner | log, resulting action, retained records, change review | Requests, reports, and resulting actions are logged and retained with the relevant certificate lifecycle evidence.
This workflow helps assign CPS updates, revocation request controls, CRL/OCSP publication checks, and evidence retention before an ETSI EN 319 411-1 assessment.
Convert revocation request handling, status publication, and retention controls into assigned evidence tasks.
Resolve CPS, CRL, OCSP, short-term certificate, and audit-log questions against the cited ETSI clauses.
Review the revocation workflow, evidence gaps, and next compliance actions with Sorena.
The evidence pack should prove both the individual outcome and the service control. Include the CPS version in force, the certificate profile and serial number, the request and authorization evidence, timing evidence, decision evidence, publication evidence, and the resulting audit log entry.
EN 319 411-1 requires logging all requests and reports and the resulting action. It does not place every revocation record under the clause 6.4.6 seven-year minimum; that minimum covers CA-managed key lifecycle records and clause 6.3.4 agreement documentation. Revocation records still need the precise retention period stated in the practice statement, the applicable period notified in the terms and conditions, and protection and accessibility under EN 319 401. Do not depend on short-lived ticket comments or dashboards that cannot be reproduced for that period.
A has a validity period shorter than the CPS maximum time for processing a request. EN 319 411-1 distinguishes short-term certificates that can be revoked from those that cannot be revoked through a revocation management service. A generic workflow can mislead relying parties if it implies that every certificate profile is revocable in the same way.
For short-term certificates that cannot be revoked, the CPS must identify which certificates cannot be revoked through a service and which cannot be revoked even on the TSP's initiative. It must explain how to notify a problem and request information about it, and the TSP must record notified problems in an audit log. Separately, a certificate with the validity assured extension does not require a status service; if it contains neither a CRL distribution point nor an OCSP access location, EN 319 411-1 recommends the RFC 9608 No Available extension.
"General Policy Requirements for Trust Service Providers"
"which certificates cannot be revoked"
"Certificate and Certificate Revocation List (CRL) Profile"
"Online Certificate Status Protocol - OCSP"