Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 98 additions & 0 deletions references/etsi/ETSI_EN_319_412-2_V2.4.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
# ETSI EN 319 412-2 V2.4.1 (2025-06)

## EUROPEAN STANDARD

# Electronic Signatures and Trust Infrastructures (ESI);
## Certificate Profiles;
### Part 2: Certificate profile for certificates issued to natural persons

---

**Reference:** REN/ESI-0019412-2v241

**Keywords:** electronic signature, IP, profile, security, trust services

---

## Contents

- [1 Scope](#1-scope)
- [4 General certificate profile requirements](#4-general-certificate-profile-requirements)
- [4.2.4 Subject](#424-subject)
- [4.3.2 Key usage](#432-key-usage)
- [4.3.11 CRL distribution points](#4311-crl-distribution-points)
- [4.4.1 Authority Information Access](#441-authority-information-access)
- [5 EU Qualified Certificate requirements](#5-eu-qualified-certificate-requirements)
- [History](#history)

---

## 1 Scope

The present document specifies requirements on the content of certificates issued to natural persons. This profile builds on IETF RFC 5280 [1] for generic profiling of Recommendation ITU-T X.509 | ISO/IEC 9594-8 [i.3].

This profile supports the requirements of EU Qualified Certificates as specified in Regulation (EU) No 910/2014 [i.5] as well as other forms of certificate.

## 4 General certificate profile requirements

### 4.2.4 Subject

**NAT-4.2.4-1:** The subject field shall include the following attributes as specified in Recommendation ITU-T X.520 [6]:
- countryName
- choice of (givenName and/or surname) or pseudonym
- commonName

**NAT-4.2.4-2:** If these mandatory attributes are not sufficient to ensure Subject name uniqueness within the context of the issuer, then the serialNumber shall be present.

**NAT-4.2.4-5:** Additional attributes other than those listed above may be present.

**NAT-4.2.4-6:** When a natural person subject is associated with an organization, the subject attributes may also identify such organization using attributes such as organizationName and organizationIdentifier.

**NAT-4.2.4-15:** The commonName attribute value shall contain a name of the subject.

> **NOTE:** ETSI TS 119 412-6 references clause 4.2.4 for the subject of certificates issued to natural persons (PID, EAA, QEAA, PSBEAA providers when natural persons). ETSI TS 119 475 maps `tradeName` → commonName, `givenName` → givenName, `familyName` → surname per this clause.

### 4.3.2 Key usage

**NAT-4.3.2-1:** The key usage extension shall be present and shall contain one (and only one) of the key usage settings defined in table 1 (A, B, C, D, E or F). Type A, C or E should be used to avoid mixed usage of keys.

| Type | Non-Repudiation (Bit 1) | Digital Signature (Bit 0) | Key Encipherment or Key Agreement (Bit 2 or 4) |
|------|-------------------------|---------------------------|------------------------------------------------|
| A | X | | |
| B | X | X | |
| C | | X | |
| D | | X | X |
| E | | | X |
| F | X | X | X |

### 4.3.11 CRL distribution points

**GEN-4.3.11-1:** If CRL is supported by the issuing CA, the CRL distribution point extension shall be present in certificates.

**GEN-4.3.11-2:** If the certificate does not include any access location of an OCSP responder as specified in clause 4.4.1, and the certificate does not include the validity assured extension, then the certificate shall include a CRL distribution point extension.

### 4.4.1 Authority Information Access

**GEN-4.4.1-2:** The Authority Information Access extension shall be present.

**GEN-4.4.1-3:** The Authority Information Access extension shall include an accessMethod OID, id-ad-caIssuers, with an accessLocation value specifying at least one access location of a valid CA certificate of the issuing CA.

**GEN-4.4.1-5:** If OCSP is supported by the issuing CA, the Authority Information Access extension shall include an accessMethod OID, id-ad-ocsp, with an accessLocation value specifying at least one access location of an OCSP responder.

> **NOTE:** ETSI TS 119 412-6 clause QEA-7.2.1-04 and PSB-8.2.1-04 reference "ETSI EN 319 412-2 [5], clause 4.3.11" for OCSP requirements.

## 5 EU Qualified Certificate requirements

**QCS-5.1-1:** If certificates are issued as EU Qualified Certificates, they shall include QCStatements in accordance with ETSI EN 319 412-5 [2].

## History

| Version | Date | Description |
|---------|------|-------------|
| V2.4.1 | June 2025 | Publication |
| V2.3.1 | September 2023 | Publication |
| V2.2.1 | July 2020 | Publication |

---

**Source:** [ETSI EN 319 412-2 PDF](https://www.etsi.org/deliver/etsi_en/319400_319499/31941202/02.04.01_60/en_31941202v020401p.pdf)
162 changes: 162 additions & 0 deletions references/etsi/ETSI_EN_319_412-3_V1.3.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,162 @@
# ETSI EN 319 412-3 V1.3.1 (2023-09)

## EUROPEAN STANDARD

# Electronic Signatures and Infrastructures (ESI);
## Certificate Profiles;
### Part 3: Certificate profile for certificates issued to legal persons

---

**Reference:** REN/ESI-0019412-3

**Keywords:** electronic signature, IP, profile, security, trust services

---

**ETSI**
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la Sous-Préfecture de Grasse (06) N° w061004871

---

## Important notice

The present document can be downloaded from: https://www.etsi.org/standards-search

The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI deliverable is the one made publicly available in PDF format at www.etsi.org/deliver.

Users of the present document should be aware that the document may be subject to revision or change of status.

## Copyright Notification

**© ETSI 2023. All rights reserved.**

---

## Contents

- [1 Scope](#1-scope)
- [2 References](#2-references)
- [3 Definition of terms, symbols, abbreviations and notations](#3-definition-of-terms-symbols-abbreviations-and-notations)
- [4 Profile requirements](#4-profile-requirements)
- [Annex A (informative): Change History](#annex-a-informative-change-history)
- [History](#history)

---

## 1 Scope

The present document specifies a certificate profile for certificates issued to legal persons. The profile defined in the present document builds on requirements defined in ETSI EN 319 412-2 [2].

The present document supports the requirements of EU qualified certificates as specified in the Regulation (EU) No 910/2014 [i.3] as well as other forms of certificate.

---

## 2 References

### 2.1 Normative references

| Ref | Document |
|-----|----------|
| [1] | Recommendation ITU-T X.520 (10/2012): "Information technology - Open Systems Interconnection - The Directory: Selected attribute types". |
| [2] | ETSI EN 319 412-2: "Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 2: Certificate Profile for certificates issued to natural persons". |
| [3] | IETF RFC 5280: "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile". |

### 2.2 Informative references

| Ref | Document |
|-----|----------|
| [i.1] | Directive 1999/93/EC of the European Parliament and of the Council of 13 December 1999 on a Community framework for electronic signatures. |
| [i.2] | Recommendation ITU-T X.509 \| ISO/IEC 9594-8: "Information technology - Open Systems Interconnection - The Directory: Public-key and attribute certificate frameworks". |
| [i.3] | Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. |
| [i.4] | ETSI EN 319 412-1: "Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 1: Overview and common data structures". |

---

## 3 Definition of terms, symbols, abbreviations and notations

- **3.1 Terms:** Terms given in ETSI EN 319 412-1 [i.4] apply.
- **3.2 Symbols:** Void.
- **3.3 Abbreviations:** Abbreviations given in ETSI EN 319 412-2 [2] apply.
- **3.4 Notations:** Notations given in ETSI EN 319 412-1 [i.4] apply.

---

## 4 Profile requirements

### 4.1 Generic requirements

**LEG-4.1-1:** All certificate fields and extensions shall comply with ETSI EN 319 412-2 [2] with the amendments specified in the present document.

### 4.2 Basic certificate fields

#### 4.2.1 Subject

**LEG-4.2.1-1:** Clause 4.2.4 of ETSI EN 319 412-2 [2] shall not apply.

**LEG-4.2.1-2:** The subject field shall include at least the following attributes as specified in Recommendation ITU-T X.520 [1]:
- countryName;
- organizationName;
- organizationIdentifier; and
- commonName.

**LEG-4.2.1-3:** Only one instance of each of these attributes shall be present. Additional attributes may be present.

**LEG-4.2.1-4:** The countryName attribute shall specify the country in which the subject (legal person) is established.

**LEG-4.2.1-5:** The organizationName attribute shall contain the full registered name of the subject (legal person).

**LEG-4.2.1-6:** The organizationIdentifier attribute shall contain an identification of the subject organization different from the organization name.

**LEG-4.2.1-7:** Certificates may include one or more semantics identifiers as specified in clause 5 of ETSI EN 319 412-1 [i.4].

**LEG-4.2.1-8:** The commonName attribute value shall contain a name commonly used by the subject to represent itself. This name needs not be an exact match of the fully registered organization name.

**LEG-4.2.1-9:** If present, the size of organizationName, organizationalUnitName and commonName may be longer than the limit as stated in IETF RFC 5280 [3].

### 4.3 Standard certificate extensions

#### 4.3.1 Key usage

**LEG-4.3.1-1:** Clause 4.3.2 of ETSI EN 319 412-2 [2] shall not apply, except those parts which are referenced below.

**LEG-4.3.1-2:** Clause 4.3.2 of ETSI EN 319 412-2 [2] paragraph 1 and subsequent table 1 shall apply.

**LEG-4.3.1-3:** Certificates used to validate digital signatures over content (e.g. documents, agreements and/or transactions) that provide evidence of origin and integrity of the content shall be limited to type A, B or F.

**LEG-4.3.1-4:** Of these alternatives, type A should be used.

> **EXAMPLE:** Digital signatures which are aimed to be used as advanced electronic seals as defined in Regulation (EU) No 910/2014 [i.3] are considered to provide evidence of origin and integrity of the content.

---

## Annex A (informative): Change History

| Date | Version | Information about changes |
|------|---------|---------------------------|
| February 2020 | 1.1.2 | Implemented Change Requests on key usage and IETF RFC 5280 size limits |
| April 2020 | 1.1.3 | ESI(20)000025, ESI(20)000026: keyUsage and subject field enhancements |
| April 2023 | 1.2.2 | Updated to allocate reference number to each requirement in line with EN 319 411-1 |

---

## History

| Version | Date | Description |
|---------|------|-------------|
| V1.0.1 | July 2015 | Publication as ETSI TS 119 412-3 (Withdrawn) |
| V1.1.1 | February 2016 | Publication |
| V1.2.1 | July 2020 | Publication |
| V1.3.0 | June 2023 | EN Approval Procedure |
| V1.3.1 | September 2023 | Publication |

---

## Official PDF

- [ETSI EN 319 412-3 V1.3.1](https://www.etsi.org/deliver/etsi_en/319400_319499/31941203/01.03.01_60/en_31941203v010301p.pdf) — official document
Loading
Loading