1.2.2 已翻譯 對應原文版本:2.3.0

相關日期

跳至原文

Relevant Dates

ComplianceSection(s)Summary Description (See Full Text for Details)
2025-01-154.9.9Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance.
2025-01-153.2.2.4CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information.
2025-03-154.3.1.2The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements.
2025-03-158.7The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits.
2025-03-153.2.2.9CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified.
2025-07-153.2.2.4CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates.
2025-12-015.7.1.2CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements.
2026-03-153.2.2.4DNSSEC validation MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective.
2026-03-153.2.2.4CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.
2026-03-153.2.2.4CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates.
2026-03-154.2.2.2.2DNSSEC validation MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.
2026-03-154.2.2.2.4CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups.
2026-03-154.2.2.2.5DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.
2026-03-154.2.1Subject Identity Information validation maximum data reuse period is 398 days.
2026-03-154.2.1Domain Name and IP Address validation maximum data reuse period is 200 days.
2026-03-154.2.2CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix.
2026-03-156.3.2Maximum validity period of Subscriber Certificates is 200 days.
2026-03-157.1.2.4CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4.
2026-07-155.4.1Audit logs of verification activity MUST include specific information.
2026-09-157.1.3.2.1Sunset all remaining use of SHA-1 in Certificates and CRLs.
2026-11-153.2.2.4Authorization Domain Names must be derived based on the validation method to be used.
2027-03-153.2.2.4 and 3.2.2.5CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates.
2027-03-153.2.2.5.3CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates.
2027-03-154.2.1Domain Name and IP Address validation maximum data reuse period is 100 days.
2027-03-156.3.2Maximum validity period of Subscriber Certificates is 100 days.
2027-03-154.2.2.1.2CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657.
2027-03-154.2.2.1.2If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in RFC 7565
2028-03-153.2.2.4 and 3.2.2.5CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates.
2029-03-154.2.1Domain Name and IP Address validation maximum data reuse period is 10 days.
2029-03-156.3.2Maximum validity period of Subscriber Certificates is 47 days.
實施日期章節摘要說明(詳情請參閱章節全文)
2025-01-154.9.9用戶憑證(Subscriber Certificate)的 OCSP 回應應(MUST)於簽發後 15 分鐘內可用。
2025-01-153.2.2.4CA 不得(MUST NOT)依賴 HTTPS 網站來識別網域名稱聯絡人(Domain Contact)資訊。CA 應(MUST)依賴 IANA 來源識別網域名稱聯絡人資訊。
2025-03-154.3.1.2CA 應(SHALL)實施 Linting 流程,以測試待簽發憑證(to-be-issued Certificate)與本文件之間的技術符合性。
2025-03-158.7CA 宜(SHOULD)採用 Linting 流程,對內部稽核(Self-Audits)所選定之樣本集中的已簽發憑證進行技術準確度測試。
2025-03-153.2.2.9CA 應(MUST)在指定的情況下,從多個網路視角(Network Perspectives)佐證網域驗證(Domain Validation)與 CAA 檢查的結果。
2025-07-153.2.2.4CA 不得(MUST NOT)依賴第 3.2.2.4.2 節與第 3.2.2.4.15 節的方法來簽發用戶憑證。
2025-12-015.7.1.2CA 應(SHALL)於其 CPS 或合併式 CP/CPS 的第 5.7.1 節中聲明其大規模廢止計畫(Mass Revocation Plan)、演練及持續改進。
2026-03-153.2.2.4針對由主要網路視角(Primary Network Perspective)執行之網域授權或控管權驗證相關的所有 DNS 查詢,均應(MUST)執行 DNSSEC 驗證。
2026-03-153.2.2.4CA 不得(MUST NOT)利用內部政策,針對任何與網域授權或控管權驗證相關的 DNS 查詢,停用其 DNSSEC 驗證。
2026-03-153.2.2.4CA 不得(MUST NOT)依賴第 3.2.2.4.8 節的方法來簽發用戶憑證。
2026-03-154.2.2.2.2針對由主要網路視角(Primary Network Perspective)執行之與 CAA 紀錄檢查相關的所有 DNS 查詢,均應(MUST)執行 DNSSEC 驗證。
2026-03-154.2.2.2.4CA 不得(MUST NOT)利用內部政策,針對任何與 CAA 紀錄檢查相關的 DNS 查詢,停用其 DNSSEC 驗證。
2026-03-154.2.2.2.5由主要網路視角(Primary Network Perspective)觀察到的 DNSSEC 驗證錯誤(例如 SERVFAIL),不得(MUST NOT)被視為許可簽發之依據。
2026-03-154.2.1可重複使用主體識別資訊(Subject Identity Information)已驗證資料的最長期限為 398 日。
2026-03-154.2.1可重複使用網域名稱(Domain Name)與 IP 位址(IP Address)已驗證資料的最長期限為 200 日。
2026-03-154.2.2CA 不得(SHALL NOT)簽發以 IP 反向區域後綴(IP Reverse Zone Suffix)結尾之網域名稱的憑證。
2026-03-156.3.2用戶憑證的最長有效期(Validity Period)為 200 日。
2026-03-157.1.2.4CA 不得(MUST NOT)使用預簽憑證簽章憑證機構(Precertificate Signing CA)來簽發預簽憑證(Precertificate)。CA 不得(MUST NOT)使用第 7.1.2.4 節所規範的受技術約束之預簽憑證簽章憑證機構憑證剖繪(Technically Constrained Precertificate Signing CA Certificate Profile)來簽發憑證。
2026-07-155.4.1驗證活動的稽核紀錄(Audit logs)應(MUST)包含特定資訊。
2026-09-157.1.3.2.1淘汰(Sunset)所有還在使用 SHA-1 簽章的憑證與 CRL。
2026-11-153.2.2.4經授權網域名稱(Authorization Domain Name,ADN)必須依所使用的驗證方法決定。
2027-03-153.2.2.4 與 3.2.2.5CA 不得(MUST NOT)依賴第 3.2.2.4.16 節、第 3.2.2.4.17 節、第 3.2.2.5.2 節與第 3.2.2.5.5 節的方法來簽發用戶憑證。
2027-03-153.2.2.5.3CA 不得(MUST NOT)依賴第 3.2.2.5.3 節的方法來簽發用戶憑證。
2027-03-154.2.1可重複使用網域名稱與 IP 位址已驗證資料的最長期限為 100 日。
2027-03-156.3.2用戶憑證的最長有效期為 100 日。
2027-03-154.2.2.1.2CA 應(MUST)依 RFC 8657 規定處理 accounturi 與 validationmethods 參數。
2027-03-154.2.2.1.2若 CA 未依 RFC 8555 所述,以 ACME Account URL 識別憑證用戶的帳號,CA 應(MUST)於其憑證政策(CP)及/或憑證實務作業基準(CPS)第 4.2 節中定義其所支援的 accounturi 格式,並宜(SHOULD)遵循 RFC 7565 所定義的 acct URI scheme。
2028-03-153.2.2.4 與 3.2.2.5CA 不得(MUST NOT)依賴第 3.2.2.4.4 節、第 3.2.2.4.13 節與第 3.2.2.4.14 節的方法來簽發用戶憑證。
2029-03-154.2.1可重複使用網域名稱與 IP 位址已驗證資料的最長期限為 10 日。
2029-03-156.3.2用戶憑證的最長有效期為 47 日。