O-RAN WG11 Security Specification
Cryptography, Protocols, PKI

O-RAN WG11 Security Specification 3: Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

Implement cryptography + protocol security + PKI per O-RAN WG11 Security Requirements covering TLS + SSH + IPsec + certificate lifecycle. TLS implementation must (a) use TLS 1.2 minimum + TLS 1.3 preferred + with WG11-approved cipher suites + Perfect Forward Secrecy + certificate verification, (b) enforce minimum key sizes per WG11 cryptographic profile (RSA 2048 minimum + ECDSA P-256 minimum + ECDHE for key exchange), (c) implement OCSP stapling + or CRL checking with documented fallback, (d) protect TLS termination points against attack including downgrade + cipher manipulation + protocol negotiation abuse. SSH implementation must (a) use SSHv2 with WG11-approved cipher suites + KEX algorithms + MAC algorithms, (b) enforce strong authentication (certificate-based + or strong key-based + with multi-factor where applicable to administrative access), (c) restrict SSH access via network segregation + jump host + PAM. IPsec implementation must (a) use IKEv2 + with WG11-approved ESP/AH parameters, (b) implement secure tunnel lifecycle including rekeying + DPD + Perfect Forward Secrecy. PKI and certificate lifecycle management must (a) define certificate hierarchy + Certificate Authority (CA) selection (operator-managed CA + or industry-trusted CA) + certificate policy + CPS, (b) implement automated certificate enrollment (CMP + EST + ACME where applicable) + renewal + revocation, (c) maintain key custody + HSM where appropriate + key rotation per WG11 cryptographic lifecycle requirements, (d) integrate with monitoring for certificate expiry + revocation + anomalous issuance.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.