Electronic Signatures and Infrastructures (ESI); Global Acceptance of EU Trust Services

DTR/ESI-000123

General Information

Status
Published
Publication Date
12-Jan-2020
Current Stage
12 - Completion
Due Date
30-Nov-2019
Completion Date
13-Jan-2020
Ref Project

Buy Standard

Standard
ETSI TR 103 684 V1.1.1 (2020-01) - Electronic Signatures and Infrastructures (ESI); Global Acceptance of EU Trust Services
English language
102 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)

ETSI TR 103 684 V1.1.1 (2020-01)






TECHNICAL REPORT
Electronic Signatures and Infrastructures (ESI);
Global Acceptance of EU Trust Services

---------------------- Page: 1 ----------------------
2 ETSI TR 103 684 V1.1.1 (2020-01)



Reference
DTR/ESI-000123
Keywords
conformity, e-commerce, electronic signature,
security, trust services
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
The present document can be downloaded from:
http://www.etsi.org/standards-search
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format at www.etsi.org/deliver.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
https://portal.etsi.org/TB/ETSIDeliverableStatus.aspx
If you find errors in the present document, please send your comment to one of the following services:
https://portal.etsi.org/People/CommiteeSupportStaff.aspx
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying
and microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.

© ETSI 2020.
All rights reserved.

DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its Members.

3GPP™ and LTE™ are trademarks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and
of the oneM2M Partners.
®
GSM and the GSM logo are trademarks registered and owned by the GSM Association.
ETSI

---------------------- Page: 2 ----------------------
3 ETSI TR 103 684 V1.1.1 (2020-01)
Contents
Intellectual Property Rights . 9
Foreword . 9
Modal verbs terminology . 9
Executive summary . 9
Introduction . 10
1 Scope . 11
2 References . 11
2.1 Normative references . 11
2.2 Informative references . 11
3 Definition of terms, symbols and abbreviations . 14
3.1 Terms . 14
3.2 Symbols . 14
3.3 Abbreviations . 15
4 Study methodology . 16
4.1 Introduction . 16
4.2 Areas of comparison between trust service schemes . 17
4.3 Comparison process . 19
4.4 Equivalence versus strict compliance . 20
4.5 Study methodology. 20
5 Information Collected on Existing PKI-based trust services schemes . 20
5.1 Introduction . 20
5.2 International Legal Framework & Standards . 21
5.2.1 UNCITRAL . 21
5.2.1.1 Introduction . 21
5.2.1.2 Legal context . 21
5.2.1.3 Supervision and auditing . 21
5.2.1.4 Best practice . 22
5.2.1.5 Trust representation . 22
5.2.1.6 Identified enablers . 22
5.2.1.7 Reference Material . 23
5.2.2 ISO 21188 PKI for financial services -- Practices and policy framework . 23
5.2.2.1 Legal context . 23
5.2.2.2 Supervision and auditing . 23
5.2.2.3 Best practice . 23
5.2.2.4 Trust representation . 23
5.2.2.5 Reference material . 23
5.2.3 ISO/IEC 27099 PKI -- Practices and policy framework . 23
5.2.3.1 Legal context . 23
5.2.3.2 Supervision and auditing . 24
5.2.3.3 Best practice . 24
5.2.3.4 Trust representation . 24
5.2.3.5 Reference material . 24
5.2.4 WebTrust for CAs . 24
5.2.4.1 Legal context . 24
5.2.4.2 Supervision and auditing . 25
5.2.4.3 Best practice . 25
5.2.4.4 Trust representation . 25
5.2.4.5 Reference material . 26
5.2.5 CA/Browser Forum. 26
5.2.5.1 Legal context . 26
5.2.5.2 Supervision and auditing . 26
5.2.5.3 Best practice . 26
ETSI

---------------------- Page: 3 ----------------------
4 ETSI TR 103 684 V1.1.1 (2020-01)
5.2.5.4 Trust representation . 26
5.2.5.5 Identified enablers . 26
5.2.5.6 Identified barriers . 26
5.2.5.7 Reference material . 27
5.2.6 IMRT-WG . 27
5.2.6.1 Legal context . 27
5.2.6.2 Supervision and auditing . 27
5.2.6.3 Best Practices . 27
5.2.6.4 Trust Representation . 27
®
5.2.7 Kantara Initiative . 27
5.2.7.1 Legal context . 27
5.2.7.2 Supervision and auditing . 27
5.2.7.3 Best practice . 27
5.2.7.4 Trust representation . 28
5.2.7.5 Identified enablers . 28
5.2.7.6 Reference material . 28
5.3 Global Sector/Platform-specific PKI . 28
®
5.3.1 Adobe Approved Trust List . 28
5.3.1.1 Legal context . 28
5.3.1.2 Supervision and auditing . 28
5.3.1.3 Best practice . 29
5.3.1.4 Trust representation . 29
5.3.1.5 Identified enablers . 29
5.3.1.6 Reference material . 29
®
5.3.2 CertiPath . 29
5.3.2.1 Legal context . 29
5.3.2.2 Supervision and auditing . 30
5.3.2.3 Best practice . 30
5.3.2.4 Trust representation . 30
5.3.2.5 Reference material . 30
5.3.3 SAFE-BioPharma® . 31
5.3.3.1 Legal context . 31
5.3.3.2 Supervision and auditing . 31
5.3.3.3 Best practice . 31
5.3.3.4 Trust representation . 31
5.3.3.5 Identified enablers . 31
5.3.3.6 Identified Barriers . 31
5.3.3.7 Reference material . 31
®
5.3.4 Google Chrome . 32
5.3.4.1 Legal context . 32
5.3.4.2 Supervision and audit . 32
5.3.4.3 Best practice . 32
5.3.4.4 Trust representation . 32
5.3.4.5 Identified barriers . 32
5.3.4.6 Reference material . 32
®
5.3.5 Apple . 32
5.3.5.1 Legal context . 32
5.3.5.2 Supervision and audit . 32
5.3.5.3 Best practice . 33
5.3.5.4 Trust representation . 33
5.3.5.5 Reference material . 33
®
5.3.6 Microsoft . 33
5.3.6.1 Legal context . 33
5.3.6.2 Supervision and audit . 33
5.3.6.3 Best practice . 33
5.3.6.4 Trust representation . 33
5.3.6.5 Reference material . 33
®
5.3.7 Mozilla . 33
5.3.7.1 Legal context . 33
5.3.7.2 Supervision and audit . 34
5.3.7.3 Best practice . 34
5.3.7.4 Trust representation . 34
ETSI

---------------------- Page: 4 ----------------------
5 ETSI TR 103 684 V1.1.1 (2020-01)
5.4 South America . 34
5.4.1 Argentina . 34
5.4.1.1 Legal context . 34
5.4.1.2 Supervision and auditing . 35
5.4.1.3 Best practice . 35
5.4.1.4 Trust representation . 35
5.4.1.5 Reference material . 35
5.4.2 Bolivia . 36
5.4.2.1 Legal context . 36
5.4.2.2 Supervision and auditing . 36
5.4.2.3 Best practice . 37
5.4.2.4 Trust representation . 37
5.4.2.5 Reference material . 37
5.4.3 Brazil . 38
5.4.3.1 Legal context . 38
5.4.3.2 Supervision and auditing . 38
5.4.3.3 Best practice . 39
5.4.3.4 Trust representation . 39
5.4.3.5 Reference material . 40
5.4.4 Chile. 40
5.4.4.1 Legal context . 40
5.4.4.2 Supervision and auditing . 41
5.4.4.3 Best practice . 41
5.4.4.4 Trust representation . 42
5.4.4.5 Identified enablers . 42
5.4.4.6 Reference material . 43
5.4.5 Columbia . 43
5.4.5.1 Legal context . 43
5.4.5.2 Supervision and auditing . 44
5.4.5.3 Best practice . 44
5.4.5.4 Trust representation . 44
5.4.5.5 Reference material . 45
5.4.6 Paraguay . 45
5.4.6.1 Legal context . 45
5.4.6.2 Supervision and auditing . 46
5.4.6.3 Best practice . 46
5.4.6.4 Trust representation . 46
5.4.6.5 Reference material . 47
5.4.7 Peru . 47
5.4.7.1 Legal context . 47
5.4.7.2 Supervision and auditing . 48
5.4.7.3 Best practice . 48
5.4.7.4 Trust representation . 48
5.4.7.5 Identified enablers . 48
5.4.7.6 Reference material . 49
5.4.8 Uruguay . 49
5.4.8.1 Legal context . 49
5.4.8.2 Supervision and auditing . 49
5.4.8.3 Best practice . 50
5.4.8.4 Trust representation . 50
5.4.8.5 Reference material . 50
5.5 The Middle East & Africa . 50
5.5.1 Arab-African e-Certification Authorities Network (AAECA-Net) . 50
5.5.1.1 Legal context . 50
5.5.1.2 Supervision and auditing .
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.