NL profile
This issue contains the decisions made for the NL profile of the FSC standard.
- PKIO acts as Trust Anchor of the Group.
- Configurations for TLS need to adhere to the NCSC recommendations: https://english.ncsc.nl/publications/publications/2021/january/19/it-security-guidelines-for-transport-layer-security-2.1
- The serial number of the subject field of the X.509 certificate acts as PeerID.
- The subject field organization of the X.509 certificate acts as a Peer name.
- The serial number must contain an OIN.
- When providing URL's to CRL's: Traffic originating from a client using a certificate that is present on the CRL must be blocked
- Port 443 is used for data traffic, 8443 for management traffic.
- Both logging and delegation extensions are implemented
- A maximum of 100 grants per contract
- A DelegatedServiceContract is only valid when a ServiceConnectionGrant exists between Delegator and Service provider
- Determine the expiry date of log records
- logging is mandatory
- Use exponential backoff as retry mechanism for contracts and signatures propagation
- The Transaction ID must be an UUID v7
- The group ID for this profile is: dva-nederland
Edited by Pim Gaemers