60 likes | 179 Vues
This document outlines the updates to ETSI TS 101 733 based on the European Electronic Signature Standardisation Initiative (EESSI) and recent evaluations. The revisions aim to provide implementers greater flexibility by allowing them to select options that best meet market needs. Key changes include making the signature policy attribute optional for Basic Electronic Signatures (BES) and maintaining backward compatibility with earlier standards. The document also introduces new optional attributes for attribute certificate references, for better alignment with modern requirements. Feedback on this draft is encouraged.
E N D
Formats for long term signatures Original documents RFC 3126 ETSI TS 101 733 European Electronic Signature Standardisation Initiative (EESSI) Why update TS101 733 updated by ETSI Based on review by EC evaluation of EESSI CMS updated RFC 3369 RFC 3852
EU EESSI Review Comments • Allow implementers more flexibility to choose options which best fit market requirements • Separate the Signature Format from the signature policy • Simplify the document • Document structure and editorial changes
Main Technical Changes • Signature policy attribute made optional for Basic Electronic Signature (BES) • BES = CMS + signing certificate attribute (i.e. hash+id of cert). • Backward compatibility with older versions (101 733 and RFC 3126) provided by Explicit Policy-based Electronic Signature (EPES) • EPES = BES+ signature-policy-identifier attribute • On generation conformance to either BES or EPES is required • Two new optional attributes for attribute cert refs • id-aa-ets-attrCertificateRefs • id-aa-ets-attrRefsRevocationRefs
What next • Comments welcome on Internet draft ross@secstan.com • Proposal: • Replace RFC 3126 with new RFC XXX based on the Internet draft presented to this meeting.