What does EN 319 411-2 require for trusted-list reliance?
ETSI EN 319 411-2 requires the relying-party notice to state that, as one condition for relying on the certificate as an EU Qualified Certificate, the validation is identified in the of the appropriate EU trusted-list entry for the QTSP. This is a condition of the qualified-certificate reliance path, not a general statement that every certificate chaining to the provider is qualified.
That means the public reliance message should name the trusted-list dependency clearly. Under eIDAS Articles 21 and 22, a provider may begin a qualified service only after its qualified status appears in the , and each national list identifies both the QTSP and its qualified services. A certificate policy OID, CA certificate, repository page, or provider claim is not enough by itself.
- Put the trusted-list condition in the relying-party notice or the terms and conditions referenced by that notice.
- Tie the claim to the QTSP and qualified trust service entry, not only to a generic provider name or certificate chain.
- Keep the certificate policy identifier visible because EN 319 411-2 says policy identifiers help relying parties assess suitability and trustworthiness under eIDAS.
- Reject the qualified-certificate conclusion when the listed service type does not cover the certificate, the relevant service status was not qualified at the validation time, the chain does not connect through the listed service identity, or certificate validity and revocation checks fail.
OVR-6.3.5-12 requires the notice to relying parties to explain that the validation trust anchor is identified in the service digital identifier of an appropriate EU trusted-list entry.
Consolidated Articles 21 and 22 establish when a qualified service may begin and require national trusted lists to identify qualified providers and their qualified services.