1.2.2 已翻譯 對應原文版本:2.3.0
相關日期
Relevant Dates
Compliance Section(s) Summary Description (See Full Text for Details) 2025-01-15 4.9.9 Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance. 2025-01-15 3.2.2.4 CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information. 2025-03-15 4.3.1.2 The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements. 2025-03-15 8.7 The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits. 2025-03-15 3.2.2.9 CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified. 2025-07-15 3.2.2.4 CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates. 2025-12-01 5.7.1.2 CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements. 2026-03-15 3.2.2.4 DNSSEC validation MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective. 2026-03-15 3.2.2.4 CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control. 2026-03-15 3.2.2.4 CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates. 2026-03-15 4.2.2.2.2 DNSSEC validation MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective. 2026-03-15 4.2.2.2.4 CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups. 2026-03-15 4.2.2.2.5 DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue. 2026-03-15 4.2.1 Subject Identity Information validation maximum data reuse period is 398 days. 2026-03-15 4.2.1 Domain Name and IP Address validation maximum data reuse period is 200 days. 2026-03-15 4.2.2 CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix. 2026-03-15 6.3.2 Maximum validity period of Subscriber Certificates is 200 days. 2026-03-15 7.1.2.4 CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4. 2026-07-15 5.4.1 Audit logs of verification activity MUST include specific information. 2026-09-15 7.1.3.2.1 Sunset all remaining use of SHA-1 in Certificates and CRLs. 2026-11-15 3.2.2.4 Authorization Domain Names must be derived based on the validation method to be used. 2027-03-15 3.2.2.4 and 3.2.2.5 CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates. 2027-03-15 3.2.2.5.3 CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates. 2027-03-15 4.2.1 Domain Name and IP Address validation maximum data reuse period is 100 days. 2027-03-15 6.3.2 Maximum validity period of Subscriber Certificates is 100 days. 2027-03-15 4.2.2.1.2 CAs MUST process the accounturiandvalidationmethodsparameters as specified in RFC 8657.2027-03-15 4.2.2.1.2 If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturiin Section 4.2 of their CP and/or CPS, and SHOULD comply with theacctURI scheme defined in RFC 75652028-03-15 3.2.2.4 and 3.2.2.5 CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates. 2029-03-15 4.2.1 Domain Name and IP Address validation maximum data reuse period is 10 days. 2029-03-15 6.3.2 Maximum validity period of Subscriber Certificates is 47 days.
| 實施日期 | 章節 | 摘要說明(詳情請參閱章節全文) |
|---|---|---|
| 2025-01-15 | 4.9.9 | 用戶憑證(Subscriber Certificate)的 OCSP 回應應(MUST)於簽發後 15 分鐘內可用。 |
| 2025-01-15 | 3.2.2.4 | CA 不得(MUST NOT)依賴 HTTPS 網站來識別網域名稱聯絡人(Domain Contact)資訊。CA 應(MUST)依賴 IANA 來源識別網域名稱聯絡人資訊。 |
| 2025-03-15 | 4.3.1.2 | CA 應(SHALL)實施 Linting 流程,以測試待簽發憑證(to-be-issued Certificate)與本文件之間的技術符合性。 |
| 2025-03-15 | 8.7 | CA 宜(SHOULD)採用 Linting 流程,對內部稽核(Self-Audits)所選定之樣本集中的已簽發憑證進行技術準確度測試。 |
| 2025-03-15 | 3.2.2.9 | CA 應(MUST)在指定的情況下,從多個網路視角(Network Perspectives)佐證網域驗證(Domain Validation)與 CAA 檢查的結果。 |
| 2025-07-15 | 3.2.2.4 | CA 不得(MUST NOT)依賴第 3.2.2.4.2 節與第 3.2.2.4.15 節的方法來簽發用戶憑證。 |
| 2025-12-01 | 5.7.1.2 | CA 應(SHALL)於其 CPS 或合併式 CP/CPS 的第 5.7.1 節中聲明其大規模廢止計畫(Mass Revocation Plan)、演練及持續改進。 |
| 2026-03-15 | 3.2.2.4 | 針對由主要網路視角(Primary Network Perspective)執行之網域授權或控管權驗證相關的所有 DNS 查詢,均應(MUST)執行 DNSSEC 驗證。 |
| 2026-03-15 | 3.2.2.4 | CA 不得(MUST NOT)利用內部政策,針對任何與網域授權或控管權驗證相關的 DNS 查詢,停用其 DNSSEC 驗證。 |
| 2026-03-15 | 3.2.2.4 | CA 不得(MUST NOT)依賴第 3.2.2.4.8 節的方法來簽發用戶憑證。 |
| 2026-03-15 | 4.2.2.2.2 | 針對由主要網路視角(Primary Network Perspective)執行之與 CAA 紀錄檢查相關的所有 DNS 查詢,均應(MUST)執行 DNSSEC 驗證。 |
| 2026-03-15 | 4.2.2.2.4 | CA 不得(MUST NOT)利用內部政策,針對任何與 CAA 紀錄檢查相關的 DNS 查詢,停用其 DNSSEC 驗證。 |
| 2026-03-15 | 4.2.2.2.5 | 由主要網路視角(Primary Network Perspective)觀察到的 DNSSEC 驗證錯誤(例如 SERVFAIL),不得(MUST NOT)被視為許可簽發之依據。 |
| 2026-03-15 | 4.2.1 | 可重複使用主體識別資訊(Subject Identity Information)已驗證資料的最長期限為 398 日。 |
| 2026-03-15 | 4.2.1 | 可重複使用網域名稱(Domain Name)與 IP 位址(IP Address)已驗證資料的最長期限為 200 日。 |
| 2026-03-15 | 4.2.2 | CA 不得(SHALL NOT)簽發以 IP 反向區域後綴(IP Reverse Zone Suffix)結尾之網域名稱的憑證。 |
| 2026-03-15 | 6.3.2 | 用戶憑證的最長有效期(Validity Period)為 200 日。 |
| 2026-03-15 | 7.1.2.4 | CA 不得(MUST NOT)使用預簽憑證簽章憑證機構(Precertificate Signing CA)來簽發預簽憑證(Precertificate)。CA 不得(MUST NOT)使用第 7.1.2.4 節所規範的受技術約束之預簽憑證簽章憑證機構憑證剖繪(Technically Constrained Precertificate Signing CA Certificate Profile)來簽發憑證。 |
| 2026-07-15 | 5.4.1 | 驗證活動的稽核紀錄(Audit logs)應(MUST)包含特定資訊。 |
| 2026-09-15 | 7.1.3.2.1 | 淘汰(Sunset)所有還在使用 SHA-1 簽章的憑證與 CRL。 |
| 2026-11-15 | 3.2.2.4 | 經授權網域名稱(Authorization Domain Name,ADN)必須依所使用的驗證方法決定。 |
| 2027-03-15 | 3.2.2.4 與 3.2.2.5 | CA 不得(MUST NOT)依賴第 3.2.2.4.16 節、第 3.2.2.4.17 節、第 3.2.2.5.2 節與第 3.2.2.5.5 節的方法來簽發用戶憑證。 |
| 2027-03-15 | 3.2.2.5.3 | CA 不得(MUST NOT)依賴第 3.2.2.5.3 節的方法來簽發用戶憑證。 |
| 2027-03-15 | 4.2.1 | 可重複使用網域名稱與 IP 位址已驗證資料的最長期限為 100 日。 |
| 2027-03-15 | 6.3.2 | 用戶憑證的最長有效期為 100 日。 |
| 2027-03-15 | 4.2.2.1.2 | CA 應(MUST)依 RFC 8657 規定處理 accounturi 與 validationmethods 參數。 |
| 2027-03-15 | 4.2.2.1.2 | 若 CA 未依 RFC 8555 所述,以 ACME Account URL 識別憑證用戶的帳號,CA 應(MUST)於其憑證政策(CP)及/或憑證實務作業基準(CPS)第 4.2 節中定義其所支援的 accounturi 格式,並宜(SHOULD)遵循 RFC 7565 所定義的 acct URI scheme。 |
| 2028-03-15 | 3.2.2.4 與 3.2.2.5 | CA 不得(MUST NOT)依賴第 3.2.2.4.4 節、第 3.2.2.4.13 節與第 3.2.2.4.14 節的方法來簽發用戶憑證。 |
| 2029-03-15 | 4.2.1 | 可重複使用網域名稱與 IP 位址已驗證資料的最長期限為 10 日。 |
| 2029-03-15 | 6.3.2 | 用戶憑證的最長有效期為 47 日。 |