21 Code For Federal Regulation Parts 1305, 1311 Page 65

ADVERTISEMENT

(c) A system used to receive, verify, and create linked records for orders signed with a
CSOS digital certificate must meet the following requirements:
(1) The cryptographic module must be FIPS 140-2, Level 1 validated.
(2) The digital signature system and hash function must be compliant with FIPS 186-2
and FIPS 180-2.
(3) The system must determine that an order has not been altered during transmission.
The system must invalidate any order that has been altered.
(4) The system must validate the digital signature using the signer’s public key. The
system must invalidate any order in which the digital signature cannot be validated.
(5) The system must validate that the DEA registration number contained in the body of
the order corresponds to the registration number associated with the specific certificate by
separately generating the hash value of the registration number and certificate subject
distinguished name serial number and comparing that hash value to the hash value contained in
the certificate extension for the DEA registration number. If the hash values are not equal the
system must invalidate the order.
(6) The system must check the Certificate Revocation List automatically and invalidate
any order with a certificate listed on the Certificate Revocation List.
(7) The system must check the validity of the certificate and the Certification Authority
certificate and invalidate any order that fails these validity checks.
(8) The system must have a time system that is within five minutes of the official
National Institute of Standards and Technology time source.
65

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Legal