概要
Overview
This document describes an integrated set of technologies, protocols, identity-proofing, lifecycle management, and auditing requirements that are necessary (but not sufficient) for the issuance and management of Publicly-Trusted TLS Server Certificates; Certificates that are trusted by virtue of the fact that their corresponding Root Certificate is distributed in widely-available application software. The requirements are not mandatory for Certification Authorities unless and until they become adopted and enforced by relying-party Application Software Suppliers.
本文件描述了一套整合技術、協定、身分查核(identity-proofing)、生命週期管理(lifecycle management)以及稽核要求(auditing requirements)之規範,這些要素皆為簽發(issuance)與管理公開信賴 TLS 伺服器憑證(Publicly-Trusted TLS Server Certificates)所必要(但非充分)之條件;憑證(Certificates)之所以受到信賴,是由於其對應之根憑證(Root Certificate)已內建於廣泛使用的應用軟體(application software)中。除非作為信賴憑證者(Relying Party)的應用軟體供應商(Application Software Suppliers)採納並強制執行本文件要求規定,否則這些要求對於憑證機構(Certification Authority,CA)並不具強制性。
Notice to Readers
The CP for the Issuance and Management of Publicly-Trusted TLS Server Certificates describe a subset of the requirements that a Certification Authority must meet in order to issue Publicly Trusted TLS Server Certificates. This document serves two purposes: to specify Baseline Requirements and to provide guidance and requirements for what a CA should include in its CPS. Except where explicitly stated otherwise, these Requirements apply only to relevant events that occur on or after 2012-07-01 (the original effective date of these requirements).
讀者須知(Notice to Readers)
公開信賴 TLS 伺服器憑證簽發與管理之憑證政策(Certificate Policy,CP)描述憑證機構(Certification Authority,CA)簽發公開信賴 TLS 伺服器憑證所應符合之要求的一部分內容。本文件具有兩個目的:明定《基本要求》(Baseline Requirements)內容以及針對 CA 在其憑證實務作業基準(Certification Practice Statement,CPS)中宜包含的內容提供指引與要求。除非另有明確說明,否則本文件要求規定僅適用於 2012-07-01(本文件的原始生效日(effective date))或之後發生的相關事件。
These Requirements do not address all of the issues relevant to the issuance and management of Publicly-Trusted TLS Server Certificates. In accordance with RFC 3647 and to facilitate a comparison of other certificate policies and CPSs (e.g. for policy mapping), this document includes all sections of the RFC 3647 framework. However, rather than beginning with a “no stipulation” comment in all empty sections, the CA/Browser Forum is leaving such sections initially blank until a decision of “no stipulation” is made. The CA/Browser Forum may update these Requirements from time to time, in order to address both existing and emerging threats to online security. In particular, it is expected that a future version will contain more formal and comprehensive audit requirements for delegated functions.
本文件並未涵蓋簽發與管理公開信賴 TLS 伺服器憑證過程中所涉及的全部議題。為了依循 RFC 3647 規範,且利於與其他憑證政策(CP)及憑證實務作業基準(CPS)進行比對(例如用於政策對應(policy mapping)),本文件包含 RFC 3647 架構之所有章節。然而,CA/Browser Forum 並非在所有空白章節中皆以「不作規定」(no stipulation)註解開頭,而是將此類章節先保持空白,直到做出「不作規定」的決定為止。CA/Browser Forum 得不定期更新本文件要求規定,以因應現有及新興的網路安全(online security)威脅。具體而言,預計未來版本將針對受委託作業(delegated functions)包含更正式且全面的稽核要求(audit requirements)。
These Requirements only address Certificates intended to be used for authenticating servers accessible through the Internet. Similar requirements for code signing, S/MIME, time-stamping, VoIP, IM, Web services, etc. may be covered in future versions.
本文件要求規定僅針對用於鑑別(authenticating)可透過網際網路(Internet)存取之伺服器的憑證。針對程式碼簽章(code signing)、S/MIME、時戳(time-stamping)、VoIP、IM、Web 服務(Web services)等類似要求,可能會在未來版本中涵蓋。
These Requirements do not address the issuance, or management of Certificates by enterprises that operate their own Public Key Infrastructure for internal purposes only, and for which the Root Certificate is not distributed by any Application Software Supplier.
本文件要求規定不涉及企業(enterprises)僅供內部用途(internal purposes)而自行營運的公開金鑰基礎建設(Public Key Infrastructure,PKI),及其所進行的憑證簽發或管理,且其根憑證(Root Certificate)未經任何應用軟體供應商(Application Software Supplier)配發。
These Requirements are applicable to all Certification Authorities within a chain of trust. They are to be flowed down from the Root Certification Authority through successive Subordinate Certification Authorities.
本文件要求規定適用憑證信賴鏈(chain of trust)中的所有憑證機構(Certification Authorities)。這些要求應從根憑證機構(Root Certification Authority)向下傳遞至各級的下屬憑證機構(Subordinate Certification Authorities)。