1.6.1 已翻譯 對應原文版本:2.3.0

名詞定義

跳至原文

Definitions

Affiliate: A corporation, partnership, joint venture or other entity controlling, controlled by, or under common control with another entity, or an agency, department, political subdivision, or any entity operating under the direct control of a Government Entity.

關係企業/關係組織(Affiliate):係指公司、合夥企業、合資企業或其他實體,且該實體控制他實體、受他實體控制,或與他實體受共同控制;亦指政府機關、部門、各級自治團體,或在政府機關直接控制下運作之任何實體。

Applicant: The natural person or Legal Entity that applies for (or seeks renewal of) a Certificate. Once the Certificate is issued, the Applicant is referred to as the Subscriber. For Certificates issued to devices, the Applicant is the entity that controls or operates the device named in the Certificate, even if the device is sending the actual certificate request.

申請者(Applicant):係指申請(或尋求展期)憑證之自然人或法人(Legal Entity)。憑證一旦核發,申請者即稱為用戶(Subscriber)。針對核發給裝置之憑證,申請者係指控管或營運該憑證所載裝置之實體,縱使該憑證申請實際上是由該裝置所發出。

Applicant Representative: A natural person or human sponsor who is either the Applicant, employed by the Applicant, or an authorized agent who has express authority to represent the Applicant:

  1. who signs and submits, or approves a certificate request on behalf of the Applicant, and/or
  2. who signs and submits a Subscriber Agreement on behalf of the Applicant, and/or
  3. who acknowledges the Terms of Use on behalf of the Applicant when the Applicant is an Affiliate of the CA or is the CA.

申請者代表(Applicant Representative):係指本身為申請者、受雇於申請者,或經明確授權可代表申請者之代理人的自然人或 Human Sponsor(資產保管人),且符合下列任一項或多項條件:

  1. 代表申請者簽署並提出、或同意憑證申請;及/或
  2. 代表申請者簽署並提出用戶協議(Subscriber Agreement);及/或
  3. 當申請者為憑證機構之關係企業或即為憑證機構本身時,代表申請者確認使用條款(Terms of Use)。

Application Software Supplier: A supplier of Internet browser software or other relying-party application software that displays or uses Certificates and incorporates Root Certificates.

應用軟體供應商(Application Software Supplier):提供網際網路瀏覽器軟體或其他作為信賴憑證者的應用軟體之供應商,其軟體會顯示或使用憑證,並內建根憑證(Root Certificates)。

Attestation Letter: A letter attesting that Subject Information is correct written by an accountant, lawyer, government official, or other reliable third party customarily relied upon for such information.

證明信函(Attestation Letter):係指由會計師、律師、政府官員或依慣例在此類資訊上具備可信度之可靠第三方所撰寫,用以證實主體資訊(Subject Information)為正確之信函。

Audit Period: In a period-of-time audit, the period between the first day (start) and the last day of operations (end) covered by the auditors in their engagement. (This is not the same as the period of time when the auditors are on-site at the CA.) The coverage rules and maximum length of audit periods are defined in Section 8.1.

稽核期間(Audit Period):於一段期間之稽核(period-of-time audit)中,稽核者於其委任案件中所涵蓋之作業首日(開始)至最後一日(結束)之期間。(此期間不等同稽核者在憑證機構實地稽核期間。)稽核期間之涵蓋規則與最長期限見第 8.1 節。

Audit Report: A report from a Qualified Auditor stating the Qualified Auditor’s opinion on whether an entity’s processes and controls comply with the mandatory provisions of these Requirements.

稽核報告(Audit Report):由合格稽核業者(Qualified Auditor)所出具之報告,用以說明被稽核實體之流程與控管措施是否遵循本文件要求規定的強制性規定之意見。

Authorization Domain Name: The FQDN used to perform validation of domain authorization or control for a given FQDN or Wildcard Domain Name.

經授權網域名稱(ADN, Authorization Domain Name):係指用以對指定之完全吻合網域名稱(FQDN)或萬用網域名稱(Wildcard Domain Name)執行網域授權或控管權驗證之 FQDN。

Authorized Ports: One of the following ports: 80 (http), 443 (https), 25 (smtp), 22 (ssh).

授權連接埠(Authorized Ports):下列連接埠之一:80(http)、443(https)、25(smtp)、22(ssh)。

Base Domain Name: The portion of a given FQDN that is the first Domain Name node left of a registry-controlled or public suffix plus the registry-controlled or public suffix (e.g. “example.co.uk” or “example.com”). For FQDNs where the right-most Domain Name node is a gTLD having ICANN Specification 13 in its registry agreement, the gTLD itself may be used as the Base Domain Name.

基礎網域名稱(Base Domain Name):於指定之完全吻合網域名稱(FQDN)中,位於註冊表控制網域或公開字尾(registry-controlled or public suffix)左方第一個網域名稱節點(Domain Name node),加上該註冊表控制網域或公開字尾之部分(例如「example.co.uk」或「example.com」)。若 FQDN 最右端之網域名稱節點在其註冊協議(registry agreement)中具備 ICANN 規格 13(Specification 13)之通用頂級網域名稱(gTLD),則該 gTLD 本身可被當作基礎網域名稱。

CAA: From RFC 8659: “The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain name. CAA Resource Records allow a public CA to implement additional controls to reduce the risk of unintended certificate mis-issue.”

授權憑證機構簽發憑證(CAA):節錄自 RFC 8659:「授權憑證機構簽發憑證(Certification Authority Authorization,CAA) DNS 資源紀錄(DNS Resource Record)允許 DNS 網域名稱持有人指定一個或多個憑證機構(CA)取得授權幫該網域名稱簽發憑證。CAA 資源紀錄允許公開 CA 實施額外的控管措施,以降低非預期憑證誤發之風險。」

CA Key Pair: A Key Pair where the Public Key appears as the Subject Public Key Info in one or more Root CA Certificate(s) and/or Subordinate CA Certificate(s).

CA 金鑰對(CA Key Pair):其公開金鑰資訊被記載於一個或多個憑證機構的根憑證及/或下屬憑證機構憑證中的 Subject Public Key Info 欄位之金鑰對。

Certificate: An electronic document that uses a digital signature to bind a public key and an identity.

憑證(Certificate):係指以數位簽章繫結公開金鑰與特定身分之電子文件。

Certificate Data: Certificate requests and data related thereto (whether obtained from the Applicant or otherwise) in the CA’s possession or control or to which the CA has access.

憑證資料(Certificate Data):由憑證機構持有、控管或可存取之憑證申請及其相關資料(無論取自申請者或其他來源)。

Certificate Management Process: Processes, practices, and procedures associated with the use of keys, software, and hardware, by which the CA verifies Certificate Data, issues Certificates, maintains a Repository, and revokes Certificates.

憑證管理流程(Certificate Management Process):憑證機構用於驗證憑證資料、簽發憑證、維護儲存庫與廢止憑證所涉及之流程、實務與程序,包括金鑰、軟體與硬體之使用。

Certificate Policy: A set of rules that indicates the applicability of a named Certificate to a particular community and/or PKI implementation with common security requirements.

憑證政策(CP, Certificate Policy):指一套規則,用以說明特定憑證對於特定社群及/或具有共同安全需求之公開金鑰基礎建設(PKI)運用的適用性。

Certificate Problem Report: Complaint of suspected Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, or inappropriate conduct related to Certificates.

憑證問題報告(Certificate Problem Report):針對疑似金鑰遭破解(Key Compromise)、憑證遭誤用(misuse)或其他與憑證相關之詐騙、破解、濫用或不當行為之投訴。

Certificate Profile: A set of documents or files that defines Certificate content and Certificate extensions, e.g. a Section in a CA’s CPS or a certificate template file used by CA software.

憑證剖繪(Certificate Profile):係指一組文件或檔案,用以定義憑證內容與憑證擴充欄位,例如憑證機構(CA)之憑證實務作業基準中的某一章節或 CA 軟體所使用的憑證模板檔案。

Certificate Revocation List: A regularly updated time-stamped list of revoked Certificates that is created and digitally signed by the CA that issued the Certificates.

憑證廢止清冊(CRL, Certificate Revocation List):由簽發憑證之憑證機構建立並以數位方式簽章,且定期更新時間戳記之已廢止憑證清單。

Certification Authority: An organization that is responsible for the creation, issuance, revocation, and management of Certificates. The term applies equally to both Root CAs and Subordinate CAs.

憑證機構(CA, Certification Authority):負責憑證之建立、簽發、廢止與管理之組織。本詞同時適用根憑證機構(Root CA)與下屬憑證機構(Subordinate CA)。

Certification Practice Statement: One of several documents forming the governance framework in which Certificates are created, issued, managed, and used.

憑證實務作業基準(CPS, Certification Practice Statement):構成憑證建立、簽發、管理及運用之治理架構的若干文件之一。

Control: “Control” (and its correlative meanings, “controlled by” and “under common control with”) means possession, directly or indirectly, of the power to: (1) direct the management, personnel, finances, or plans of such entity; (2) control the election of a majority of the directors; or (3) vote that portion of voting shares required for “control” under the law of the entity’s Jurisdiction of Incorporation or Registration but in no case less than 10%.

控制(Control):「控制」(及其相關用語「受其控制(controlled by)」與「與其受共同控制(under common control with)),係指直接或間接擁有下列權力之一:(1) 主導該實體之經營、人事、財務或計畫;(2) 控制過半董事之選任;或 (3) 表決權依該實體設立地或註冊地管轄法律中構成「控制」所需之表決權股份比例,但無論如何不得少於 10%。

Country: Either a member of the United Nations OR a geographic region recognized as a Sovereign State by at least two UN member nations.

國家(Country):聯合國會員國,或(OR)經至少兩個聯合國會員國承認為主權國家(Sovereign State)之地理區域。

Cross-Certified Subordinate CA Certificate: A certificate that is used to establish a trust relationship between two CAs.

交互認證之下屬憑證機構憑證(Cross-Certified Subordinate CA Certificate):於兩個憑證機構之間建立信賴關係的憑證。

CSPRNG: A random number generator intended for use in a cryptographic system.

密碼學安全偽亂數產生器(CSPRNG):供密碼學系統使用之亂數產生器。

Delegated Third Party: A natural person or Legal Entity that is not the CA but is authorized by the CA, and whose activities are not within the scope of the appropriate CA audits, to assist in the Certificate Management Process by performing or fulfilling one or more of the CA requirements found herein.

受委任第三方(Delegated Third Party):非屬憑證機構(CA)之自然人或法人(Legal Entity),獲 CA 授權執行或履行本文件所列之一項或多項 CA 要求事項,以協助憑證管理流程,且其相關活動未納入 CA 稽核適用範圍。

DNS CAA Email Contact: The email address defined in Appendix A.1.1.

DNS CAA 電子郵件聯絡人(DNS CAA Email Contact):附錄 A.1.1所定義的電子郵件地址。

DNS CAA Phone Contact: The phone number defined in Appendix A.1.2.

DNS CAA 電話聯絡人(DNS CAA Phone Contact):附錄 A.1.2所定義的電話號碼。

DNS TXT Record Email Contact: The email address defined in Appendix A.2.1.

DNS TXT 紀錄電子郵件聯絡人(DNS TXT Record Email Contact):附錄 A.2.1所定義的電子郵件地址。

DNS TXT Record Phone Contact: The phone number defined in Appendix A.2.2.

DNS TXT 紀錄電話聯絡人(DNS TXT Record Phone Contact):附錄 A.2.2所定義的電話號碼。

Domain Label: From RFC 8499: “An ordered list of zero or more octets that makes up a portion of a domain name. Using graph theory, a label identifies one node in a portion of the graph of all possible domain names.”

網域標籤(Domain Label):節錄自 RFC 8499:「由零個或多個位元組(octet)依序組合而成,用以構成網域名稱的一部分。以圖論(Graph theory)表示時,網域標籤用於識別所有可能的網域名稱所構成之圖形結構中的一個節點。」

Domain Name: An ordered list of one or more Domain Labels assigned to a node in the Domain Name System.

網域名稱(Domain Name):由一個或多個網域標籤(Domain Label)依序組合而成,並被當作網域名稱系統(DNS)中的一個節點。

Domain Namespace: The set of all possible Domain Names that are subordinate to a single node in the Domain Name System.

網域名稱空間(Domain Namespace):網域名稱系統中(DNS)中,一個節點轄下之所有可能的網域名稱之集合。

Domain Name Registrant: Sometimes referred to as the “owner” of a Domain Name, but more properly the person(s) or entity(ies) registered with a Domain Name Registrar as having the right to control how a Domain Name is used, such as the natural person or Legal Entity that is listed as the “Registrant” by WHOIS or the Domain Name Registrar.

網域名稱註冊人(Domain Name Registrant):有時被稱為網域名稱的「擁有者(owner)」,但更精確而言,係指個人或實體被網域名稱註冊商(Domain Name Registrar)註冊為具有權利控管網域名稱使用方式之個人或實體,例如於 WHOIS 查詢或網域名稱註冊商資料中被列在「Registrant」之自然人或法人。

Domain Name Registrar: A person or entity that registers Domain Names under the auspices of or by agreement with:

  1. the Internet Corporation for Assigned Names and Numbers (ICANN),
  2. a national Domain Name authority/registry, or
  3. a Network Information Center (including their affiliates, contractors, delegates, successors, or assignees).

網域名稱註冊商(Domain Name Registrar):經下列機構授權或與其簽訂協議,而辦理網域名稱註冊之個人或實體:

  1. 網際網路名稱與號碼指配機構(ICANN);
  2. 國家級網域名稱主管機關或註冊管理機構(authority/registry);或
  3. 網路資訊中心(Network Information Center, NIC)(包括其關係企業、承包商、受委任單位、繼承人或受讓人)。

Enterprise RA: An employee or agent of an organization unaffiliated with the CA who authorizes issuance of Certificates to that organization.

企業註冊中心(Enterprise RA):與憑證機構無關聯之組織的員工或代理人,獲授權向該組織核准憑證之簽發。

Expiry Date: The “Not After” date in a Certificate that defines the end of a Certificate’s validity period.

到期日(Expiry Date):憑證中「Not After」欄位之日期,定義憑證有效期之終止。

Fully-Qualified Domain Name: A Domain Name that includes the Domain Labels of all superior nodes in the Internet Domain Name System.

完全吻合網域名稱(FQDN, Fully-Qualified Domain Name):指包含其所有於DNS上層節點之網域標籤的完整網域名稱。

Government Entity: A government-operated legal entity, agency, department, ministry, branch, or similar element of the government of a country, or political subdivision within such country (such as a state, province, city, county, etc.).

政府機關(Government Entity):由政府設立或運作之法人、機關、部門、部會、分支機構或其他類似之政府組織,以及該國轄下各級地方自治團體(如州、省、市、縣等)。

High Risk Certificate Request: A Request that the CA flags for additional scrutiny by reference to internal criteria and databases maintained by the CA, which may include names at higher risk for phishing or other fraudulent usage, names contained in previously rejected certificate requests or revoked Certificates, names listed on the Miller Smiles phishing list or the Google Safe Browsing list, or names that the CA identifies using its own risk-mitigation criteria.

高風險憑證申請(High Risk Certificate Request):指憑證機構(CA)依內部準則及所維護的資料庫內容,將某一憑證申請標示為須額外審查之申請。相關準則及資料庫收錄容易遭用於網路釣魚或其他詐欺用途之主體名稱、曾出現於遭拒絕之憑證申請或已廢止憑證的主體名稱、被列在 Miller Smiles Phishing List 或 Google Safe Browsing List 中之網域名稱,或 CA 依其自身風險減輕準則所識別之名稱。

Internal Name: A string of characters (not an IP address) in a Common Name or Subject Alternative Name field of a Certificate that cannot be verified as globally unique within the public DNS at the time of certificate issuance because it does not end with a Top-Level Domain registered in IANA’s Root Zone Database.

內部名稱(Internal Name):指憑證之 Common Name 或 Subject Alternative Name 欄位中的字串(非 IP 位址),由於其並非使用登記於 IANA Root Zone Database 的頂級網域名稱(Top-Level Domain, TLD)作為結尾,故於憑證簽發時無法在公開 DNS 中驗證其具有全球唯一性。

IP Address: A 32-bit or 128-bit number assigned to a device that uses the Internet Protocol for communication.

IP 位址(IP Address):指配給使用網際網路協定(Internet Protocol, IP)進行通訊之裝置的 32 位元或 128 位元數值。

IP Address Contact: The person(s) or entity(ies) registered with an IP Address Registration Authority as having the right to control how one or more IP Addresses are used.

IP 位址聯絡人(IP Address Contact):經 IP 位址註冊管理機構登記為有權控管一個或多個 IP 位址使用方式之個人或實體。

IP Address Registration Authority: The Internet Assigned Numbers Authority (IANA) or a Regional Internet Registry (RIPE, APNIC, ARIN, AfriNIC, LACNIC).

IP 位址註冊管理機構(IP Address Registration Authority):網際網路號碼分配機構(IANA)或區域網際網路註冊管理機構(RIPE、APNIC、ARIN、AfriNIC、LACNIC)。

IP Reverse Zone Suffix: One of the two FQDNs that consist of the Domain Labels “in-addr.arpa” or “ip6.arpa”. These two FQDNs serve as the root of the IP version 4 and IP version 6 reverse mapping space. “in-addr.arpa” is the root of the IP version 4 reverse mapping space and “ip6.arpa” is the root of the IP version 6 reverse mapping space.

IP 反向區域後綴(IP Reverse Zone Suffix):由網域標籤「in-addr.arpa」或「ip6.arpa」所構成之兩個完全吻合網域名稱(FQDN)之一。此二個 FQDN 分別作為網際網路協定第 4 版(IPv4)及第 6 版(IPv6)反向對應(Reverse Mapping)命名空間之根節點。其中,「in-addr.arpa」為 IPv4 反向對應命名空間之根節點,「ip6.arpa」則為 IPv6 反向對應命名空間之根節點。

Issuing CA: In relation to a particular Certificate, the CA that issued the Certificate. This could be either a Root CA or a Subordinate CA.

簽發憑證機構(Issuing CA):對一張憑證而言,即簽發該憑證之憑證機構(CA)。可以是根憑證機構(Root CA)或下屬憑證機構(Subordinate CA)。

Key Compromise: A Private Key is said to be compromised if its value has been disclosed to an unauthorized person, or an unauthorized person has had access to it.

金鑰遭破解(Key Compromise):當私密金鑰的數值洩漏給未經授權之人士,或未經授權之人士得以存取該私密金鑰時,即稱該私密金鑰遭破解。

Key Generation Script: A documented plan of procedures for the generation of a CA Key Pair.

金鑰產製腳本(Key Generation Script):用於產製憑證機構(CA)金鑰對之書面程序計畫。

Key Pair: The Private Key and its associated Public Key.

金鑰對(Key Pair):私密金鑰與其對應之公開金鑰。

LDH Label: From RFC 5890: “A string consisting of ASCII letters, digits, and the hyphen with the further restriction that the hyphen cannot appear at the beginning or end of the string. Like all DNS labels, its total length must not exceed 63 octets.”

LDH 標籤(LDH Label):節錄自 RFC 5890:「由 ASCII 字母、數字與連字號組成之字串,且連字號不得出現於字串開頭或結尾。如同所有 DNS 標籤,其總長度不得超過 63 個位元組(octet)。」

Legal Entity: An association, corporation, partnership, proprietorship, trust, government entity or other entity with legal standing in a country’s legal system.

法人(Legal Entity):於一國法律制度中具合法地位之社團、公司、合夥、獨資、信託、政府機關或其他實體。

Linting: A process in which the content of digitally signed data such as a Precertificate RFC 6962, Certificate, Certificate Revocation List, or OCSP response, or data-to-be-signed object such as a tbsCertificate (as described in RFC 5280, Section 4.1.1.1) is checked for conformance with the profiles and requirements defined in these Requirements.

Linting(語法檢查):針對預簽憑證(RFC 6962)、憑證、憑證廢止清冊(CRL)或線上憑證狀態協定(OCSP)回應等已完成數位簽章之資料,或待簽章的資料物件,例如 tbsCertificate(如 RFC 5280, 第 4.1.1.1 節 所述),檢查其內容是否符合本文件所定義之剖繪及要求的流程。

Multi-Perspective Issuance Corroboration: A process by which the determinations made during domain validation and CAA checking by the Primary Network Perspective are corroborated by other Network Perspectives before Certificate issuance.

多視角簽發佐證(Multi-Perspective Issuance Corroboration):於憑證簽發前,由其他網路視角(Network Perspectives)佐證主要網路視角(Primary Network Perspective)在網域驗證及 CAA 檢查時所做判定之流程。

Network Perspective: Related to Multi-Perspective Issuance Corroboration. A system (e.g., a cloud-hosted server instance) or collection of network components (e.g., a VPN and corresponding infrastructure) for sending outbound Internet traffic associated with a domain control validation method and/or CAA check. The location of a Network Perspective is determined by the point where unencapsulated outbound Internet traffic is typically first handed off to the network infrastructure providing Internet connectivity to that perspective.

網路視角(Network Perspective):與多視角簽發佐證(Multi-Perspective Issuance Corroboration)相關。指用於發送網域控管權驗證(Domain Control Validation)方法及/或 CAA 檢查相關之對外網際網路流量的系統(例如雲端代管伺服器的執行個體),或網路元件的組合(例如 VPN 及其相關基礎設施)。網路視角之位置,通常係指未封裝之對外網際網路流量首次交接給提供該視角網際網路連線之網路基礎設施的地點。

Non-Reserved LDH Label: From RFC 5890: “The set of valid LDH labels that do not have ‘--’ in the third and fourth positions.”

非保留 LDH 標籤(Non-Reserved LDH Label):節錄自 RFC 5890:「第三與第四個字元位置不含『--』之有效 LDH 標籤集合。」

Object Identifier: A unique alphanumeric or numeric identifier registered under the International Organization for Standardization’s applicable standard for a specific object or object class.

物件識別碼(OID, Object Identifier):於國際標準化組織(ISO)適用標準下,為特定物件或物件類別所註冊之唯一英數字或數字識別碼。

OCSP Responder: An online server operated under the authority of the CA and connected to its Repository for processing Certificate status requests. See also, Online Certificate Status Protocol.

OCSP 回應伺服器(OCSP Responder):係指在 CA 授權下營運的線上伺服器,並連線至其憑證儲存庫,用以處理憑證狀態之查詢請求。亦參見「線上憑證狀態協定(OCSP)」之定義。

Onion Domain Name: A Fully Qualified Domain Name ending with the RFC 7686 “.onion” Special-Use Domain Name. For example, 2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion is an Onion Domain Name, whereas torproject.org is not an Onion Domain Name.

Onion 網域名稱(Onion Domain Name):以 RFC 7686 所定義之「.onion」特殊用途網域名稱(Special-Use Domain Name)結尾之完全吻合網域名稱(FQDN)。例如,2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion 為 Onion 網域名稱,反之,torproject.org 則非 Onion 網域名稱。

Online Certificate Status Protocol: An online Certificate-checking protocol that enables relying-party application software to determine the status of an identified Certificate. See also OCSP Responder.

線上憑證狀態協定(OCSP, Online Certificate Status Protocol):係一種線上憑證檢查協定,用以使作為信賴憑證者的應用軟體得以判定某張憑證之狀態。亦參見「OCSP 回應伺服器」之定義。

Parent Company: A company that Controls a Subsidiary Company.

母公司(Parent Company):控制子公司(Subsidiary Company)之公司。

Pending Prohibition: The use of a behavior described with this label is highly discouraged, as it is planned to be deprecated and will likely be designated as MUST NOT in the future.

預告禁用(Pending Prohibition):指極不鼓勵使用描述中有此標籤之行為,因該行為已被規劃予以廢止(Deprecated),且未來極可能被指定為不得(MUST NOT)使用。

Persistent DCV TXT Record: A DNS TXT record identifying an Applicant in accordance with Section 3.2.2.4.22.

持久性網域控管權 TXT 紀錄(Persistent DCV TXT Record):依第 3.2.2.4.22 節規定,用於識別申請者之 DNS TXT 紀錄。

Precertificate: A Precertificate is a signed data structure that can be submitted to a Certificate Transparency log, as defined by RFC 6962 and containing the critical poison extension (OID: 1.3.6.1.4.1.11129.2.4.3).

預簽憑證(Precertificate):依 RFC 6962 之定義,可提出至憑證透明度(Certificate Transparency)記錄系統之已簽章資料結構,且包含關鍵性 poison 擴充欄位(OID:1.3.6.1.4.1.11129.2.4.3)。

Primary Network Perspective: The Network Perspective used by the CA to make the determination of 1) the CA’s authority to issue a Certificate for the requested domain(s) or IP address(es) and 2) the Applicant’s authority and/or domain authorization or control of the requested domain(s) or IP address(es).

主要網路視角(Primary Network Perspective):憑證機構(CA)用以判定下列事項之網路視角(1)CA 是否有權限為所申請之網域或 IP 位址簽發憑證,以及(2)申請者是否具有相關權限,及/或獲得所申請網域或 IP 位址之網域授權或控管權。

Private Key: The key of a Key Pair that is kept secret by the holder of the Key Pair, and that is used to create Digital Signatures and/or to decrypt electronic records or files that were encrypted with the corresponding Public Key.

私密金鑰(Private Key):金鑰對中由持有人保密持有之金鑰,用以建立數位簽章及/或解密其對應公開金鑰所加密之電子紀錄或檔案。

Public Key: The key of a Key Pair that may be publicly disclosed by the holder of the corresponding Private Key and that is used by a Relying Party to verify Digital Signatures created with the holder’s corresponding Private Key and/or to encrypt messages so that they can be decrypted only with the holder’s corresponding Private Key.

公開金鑰(Public Key):係指金鑰對中,私密金鑰持有人可對外公開之對應金鑰。信賴憑證者用以驗證持有人以對應私密金鑰所建立之數位簽章,及/或用以將訊息加密,使加密訊息僅能由持有人以對應私密金鑰解密。

Public Key Infrastructure: A set of hardware, software, people, procedures, rules, policies, and obligations used to facilitate the trustworthy creation, issuance, management, and use of Certificates and keys based on Public Key Cryptography.

公開金鑰基礎建設(PKI, Public Key Infrastructure):基於公開金鑰密碼學之硬體、軟體、人員、程序、規範、政策與義務之集合體,被用以協助憑證與金鑰之可信賴建立、簽發、管理及使用。

Publicly-Trusted Certificate: A Certificate that is trusted by virtue of the fact that its corresponding Root Certificate is distributed as a trust anchor in widely-available application software.

公開信賴憑證(Publicly-Trusted Certificate):因其對應之根憑證,以信賴根源(Trust Anchor)之形式配發於廣泛使用之應用軟體中,進而受到信任之憑證。

P-Label: A XN-Label that contains valid output of the Punycode algorithm (as defined in RFC 3492, Section 6.3) from the fifth and subsequent positions.

P-Label:係指自第五個字元位置起,包含 Punycode 演算法有效輸出字串(如 RFC 3492, 第 6.3 節 所定義)之 XN-Label。

Qualified Auditor: A natural person or Legal Entity that meets the requirements of Section 8.2.

合格稽核業者(Qualified Auditor):符合第 8.2 節規定之稽核資格所要求之自然人或法人。

Random Value: A value specified by a CA to the Applicant that exhibits at least 112 bits of entropy.

隨機值(Random Value):憑證機構提供予申請者的指定數值,其具備至少 112 位元之亂度(entropy,資訊熵)。

Registered Domain Name: A Domain Name that has been registered with a Domain Name Registrar.

已註冊網域名稱(Registered Domain Name):已向網域名稱註冊商登記的網域名稱。

Registration Authority (RA): Any Legal Entity that is responsible for identification and authentication of subjects of Certificates, but is not a CA, and hence does not sign or issue Certificates. An RA may assist in the certificate application process or revocation process or both. When “RA” is used as an adjective to describe a role or function, it does not necessarily imply a separate body, but can be part of the CA.

註冊中心(RA, Registration Authority):負責憑證主體之識別與鑑別,但本身非憑證機構(CA),且不簽署或簽發憑證之任何法人。註冊中心(RA)得協助憑證申請流程、憑證廢止流程,或同時協助兩者。當「RA」作為形容詞用以描述角色或功能時,並不必然表示其為獨立機構,亦可能為 CA 之一部分。

Reliable Data Source: An identification document or source of data used to verify Subject Identity Information that is generally recognized among commercial enterprises and governments as reliable, and which was created by a third party for a purpose other than the Applicant obtaining a Certificate.

可靠資料來源(Reliable Data Source):用以驗證主體識別資訊(Subject Identity Information)之識別文件或資料來源,為商業界及政府機關普遍認可之可靠來源,且係由第三方基於憑證申請以外之目的所建立。

Reliable Method of Communication: A method of communication, such as a postal/courier delivery address, telephone number, or email address, that was verified using a source other than the Applicant Representative.

可靠通訊方式(Reliable Method of Communication):以申請者代表以外之來源完成驗證的通訊方式,例如信箱/快遞地址、電話號碼或電子郵件地址。

Relying Party: Any natural person or Legal Entity that relies on a Valid Certificate. An Application Software Supplier is not considered a Relying Party when software distributed by such Supplier merely displays information relating to a Certificate.

信賴憑證者(Relying Party):信賴(使用)有效憑證之任何自然人或法人。當應用軟體供應商所發布之軟體僅顯示憑證相關資訊時,該供應商不視為信賴憑證者。

Repository: An online database containing publicly-disclosed PKI governance documents (such as Certificate Policies and Certification Practice Statements) and Certificate status information, either in the form of a CRL or an OCSP response.

儲存庫(Repository):提供公開揭露之 PKI 治理文件(例如憑證政策與憑證實務作業基準)及憑證狀態資訊之線上資料庫;憑證狀態資訊可用 CRL 或 OCSP 回應之形式提供。

Request Token: A value, derived in a method specified by the CA which binds this demonstration of control to the certificate request. The CA SHOULD define within its CPS (or a document clearly referenced by the CPS) the format and method of Request Tokens it accepts.

The Request Token SHALL incorporate the key used in the certificate request.

A Request Token MAY include a timestamp to indicate when it was created.

A Request Token MAY include other information to ensure its uniqueness.

A Request Token that includes a timestamp SHALL remain valid for no more than 30 days from the time of creation.

A Request Token that includes a timestamp SHALL be treated as invalid if its timestamp is in the future.

A Request Token that does not include a timestamp is valid for a single use and the CA SHALL NOT re-use it for a subsequent validation.

The binding SHALL use a digital signature algorithm or a cryptographic hash algorithm at least as strong as that to be used in signing the certificate request.

Note: Examples of Request Tokens include, but are not limited to:

  1. a hash of the public key; or
  2. a hash of the Subject Public Key Info [X.509]; or
  3. a hash of a PKCS#10 CSR.

A Request Token may also be concatenated with a timestamp or other data. If a CA wanted to always use a hash of a PKCS#10 CSR as a Request Token and did not want to incorporate a timestamp and did want to allow certificate key re-use then the applicant might use the challenge password in the creation of a CSR with OpenSSL to ensure uniqueness even if the subject and key are identical between subsequent requests.

Note: This simplistic shell command produces a Request Token which has a timestamp and a hash of a CSR. echo `date -u +%Y%m%d%H%M` `sha256sum <r2.csr` \| sed "s/[ -]//g" The script outputs: 201602251811c9c863405fe7675a3988b97664ea6baf442019e4e52fa335f406f7c5f26cf14f

請求符記(Request Token):依憑證機構(CA)指定方法所產生之值,用以將控管權證明與憑證申請繫結起來。CA 宜(SHOULD)於其憑證實務作業基準(或憑證實務作業基準明確引用之文件)中定義其接受之請求符記格式與產生方法。

請求符記應(SHALL)加進憑證請求所使用之金鑰。

請求符記得(MAY)包含時間戳記,以標示其建立時間。

請求符記得(MAY)包含其他資訊,以確保其唯一性。

包含時間戳記之請求符記,其有效期自建立起應(SHALL)不超過 30 日。

包含時間戳記之請求符記,若其時間戳記為未來時間,應(SHALL)視為無效。

不含時間戳記之請求符記僅供單次使用,CA 不得(SHALL NOT)於後續驗證中重複使用(re-use)。

該繫結機制應(SHALL)至少使用與憑證請求簽章所用之同等強度數位簽章演算法或密碼學雜湊演算法。

註:請求符記之範例,包括但不限於:

  1. 公開金鑰之雜湊;或
  2. Subject Public Key Info [X.509] 之雜湊;或
  3. PKCS#10 憑證請求檔(CSR)之雜湊。

請求符記亦可與時間戳記或其他資料串連。若 CA 希望一律以 PKCS#10 憑證請求檔(CSR)之雜湊作為請求符記,且不欲加進時間戳記、又欲允許憑證金鑰對重複使用,則申請者於使用 OpenSSL 建立憑證請求檔時可加入挑戰密碼(Challenge Password),以確保即使後續請求檔使用相同之主體與金鑰,仍能維持其唯一性。

註:以下這個簡單的 shell 指令會產生一個包含時間戳記與憑證請求檔(CSR)雜湊的請求符記(Request Token): echo `date -u +%Y%m%d%H%M` `sha256sum <r2.csr` \| sed "s/[ -]//g" 其指令輸出如下: 201602251811c9c863405fe7675a3988b97664ea6baf442019e4e52fa335f406f7c5f26cf14f

Required Website Content: Either a Random Value or a Request Token, together with additional information that uniquely identifies the Subscriber, as specified by the CA.

所要求的網站內容(Required Website Content):指隨機值或請求符記其中之一,連同由憑證機構指定,用以識別用戶唯一性之額外資訊。

Requirements: The Baseline Requirements found in this document.

Requirements:指本文件所載之《基本要求》(Baseline Requirements);下文視語境以「本文件」(指文件本體)或「本文件要求規定」(指其規範內容)稱之。

Reserved IP Address: An IPv4 or IPv6 address that is contained in the address block of any entry in either of the following IANA registries:

https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml

https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml

保留 IP 位址(Reserved IP Address):下列 IANA 登錄表所列位址區塊(Address Block)中之任一 IPv4 或 IPv6 位址:

https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml

https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml

Reverse Zone Domain Name: the FQDN in the .arpa namespace that corresponds to an IP address. This FQDN is constructed by converting the IP address to a sequence of labels followed by the applicable IP Reverse Zone Suffix, as specified in RFC 1035 (for IPv4 addresses) and RFC 3596 (for IPv6 addresses).

反向區域網域名稱(Reverse Zone Domain Name):於 .arpa 名稱空間中,對應某 IP 位址之完全吻合網域名稱(FQDN)。此 FQDN 係將 IP 位址轉換為一連串標籤後,附加適用之 IP 反向區域後綴所構成,如 RFC 1035(IPv4 位址)與 RFC 3596(IPv6 位址)所載。

Root CA: The top level Certification Authority whose Root Certificate is distributed by Application Software Suppliers and that issues Subordinate CA Certificates.

根憑證機構(Root CA):指頂層憑證機構,其根憑證由應用軟體供應商配發,並簽發下屬憑證機構憑證。

Root Certificate: The self-signed Certificate issued by the Root CA to identify itself and to facilitate verification of Certificates issued to its Subordinate CAs.

根憑證(Root Certificate):根憑證機構所簽發之自簽憑證,用以識別其自身,並協助驗證其對下屬憑證機構簽發之憑證。

Short-lived Subscriber Certificate: For Certificates issued on or after 2024-03-15 and prior to 2026-03-15, a Subscriber Certificate with a Validity Period less than or equal to 10 days (864,000 seconds). For Certificates issued on or after 2026-03-15, a Subscriber Certificate with a Validity Period less than or equal to 7 days (604,800 seconds).

短效期用戶憑證(Short-lived Subscriber Certificate):對於 2024-03-15 起至 2026-03-15 前簽發之憑證,指有效期小於或等於 10 日(864,000 秒)之用戶憑證。對於 2026-03-15 起簽發之憑證,指有效期小於或等於 7 日(604,800 秒)之用戶憑證。

Sovereign State: A state or country that administers its own government, and is not dependent upon, or subject to, another power.

主權國家(Sovereign State):自行管理其政府,且不依附或受制於另一政權之國家或國土。

Subject: The natural person, device, system, unit, or Legal Entity identified in a Certificate as the Subject. The Subject is either the Subscriber or a device under the control and operation of the Subscriber.

主體(Subject):憑證中被識別為「主體」之自然人、裝置、系統、單位或法人。主體為用戶本身,或受該用戶控管與營運之裝置。

Subject Identity Information: Information that identifies the Certificate Subject. Subject Identity Information does not include a Domain Name or an IP Address listed in the subjectAltName extension or the Subject commonName field.

主體識別資訊(Subject Identity Information):用以識別憑證主體的資訊。主體識別資訊不包含 subjectAltName 擴充欄位或主體 commonName 欄位所列之網域名稱或 IP 位址。

Subordinate CA: A Certification Authority whose Certificate is signed by the Root CA, or another Subordinate CA.

下屬憑證機構(Subordinate CA):其自身憑證由根憑證機構(Root CA)或其他下屬憑證機構所簽章之憑證機構。

Subscriber: A natural person or Legal Entity to whom a Certificate is issued and who is legally bound by a Subscriber Agreement or Terms of Use.

用戶(Subscriber):被簽發憑證且受用戶協議(Subscriber Agreement)或使用條款(Terms of Use)約束之自然人或法人。

Subscriber Agreement: An agreement between the CA and the Applicant/Subscriber that specifies the rights and responsibilities of the parties.

用戶協議(Subscriber Agreement):憑證機構與申請者/用戶之間的協議,載明雙方之權利義務。

Subsidiary Company: A company that is controlled by a Parent Company.

子公司(Subsidiary Company):受母公司控制之公司。

Technically Constrained Subordinate CA Certificate: A Subordinate CA certificate which uses a combination of Extended Key Usage and/or Name Constraint extensions, as defined within the relevant Certificate Profiles of this document, to limit the scope within which the Subordinate CA Certificate may issue Subscriber or additional Subordinate CA Certificates.

受技術約束的下屬憑證機構憑證(Technically Constrained Subordinate CA Certificate):指依本文件相關憑證剖繪(Certificate Profile)之規定,使用 Extended Key Usage 及/或 Name Constraints 擴充欄位之組合,限制該下屬憑證機構(CA)憑證簽發用戶憑證或其他下屬 CA 憑證之範圍。

Terms of Use: Provisions regarding the safekeeping and acceptable uses of a Certificate issued in accordance with these Requirements when the Applicant/Subscriber is an Affiliate of the CA or is the CA.

使用條款(Terms of Use):當申請者/用戶為憑證機構(CA)之關係企業或 CA 本身時,用以規範依本文件要求規定簽發之憑證的保管與允許用途。

Test Certificate: This term is no longer used in these Baseline Requirements.

測試憑證(Test Certificate):本詞已不再《基本要求》中使用。

Top-Level Domain: From RFC 8499 (https://tools.ietf.org/html/rfc8499): “A Top-Level Domain is a zone that is one layer below the root, such as “com” or “jp”.”

頂級網域(TLD, Top-Level Domain):節錄自 RFC 8499:「頂級網域為根網域下一層之區域,例如『com』或『jp』。」

Trustworthy System: Computer hardware, software, and procedures that are: reasonably secure from intrusion and misuse; provide a reasonable level of availability, reliability, and correct operation; are reasonably suited to performing their intended functions; and enforce the applicable security policy.

可信賴系統(Trustworthy System):具有下列性質之電腦硬體、軟體與程序:對於入侵與誤用有合理地保護;提供合理水準之可用性、可靠性與正確運作;合理適當地執行其預定功能;並落實適用的安全政策。

Unregistered Domain Name: A Domain Name that is not a Registered Domain Name.

未註冊網域名稱(Unregistered Domain Name):非已註冊網域名稱之網域名稱。

Valid Certificate: A Certificate that passes the validation procedure specified in RFC 5280.

有效憑證(Valid Certificate):通過 RFC 5280 所規定之驗證程序的憑證。

Validation Specialist: Someone who performs the information verification duties specified by these Requirements.

驗證專員(Validation Specialist):執行本文件所規定之資訊驗證作業的人員。

Validity Period: From RFC 5280: “The period of time from notBefore through notAfter, inclusive.”

有效期(Validity Period):節錄自 RFC 5280:「自 notBefore 至 notAfter(含)之期間。」

WHOIS: Information retrieved directly from the Domain Name Registrar or registry operator via the protocol defined in RFC 3912, the Registry Data Access Protocol defined in RFC 7482, or an HTTPS website.

WHOIS:係指透過 RFC 3912 所定義之 WHOIS 協定、RFC 7482 所定義之註冊資料存取協定(RDAP),或者透過 HTTPS 網站,直接從網域名稱註冊商或註冊管理機構取得之資訊。

Wildcard Certificate: A Certificate containing at least one Wildcard Domain Name in the Subject Alternative Names in the Certificate.

萬用網域憑證(Wildcard Certificate):在憑證主體別名/主體替代名稱中至少含有一個萬用網域名稱之憑證。

Wildcard Domain Name: A string starting with ”*.” (U+002A ASTERISK, U+002E FULL STOP) immediately followed by a Fully-Qualified Domain Name.

萬用網域名稱(Wildcard Domain Name):以「*.」(U+002A ASTERISK、U+002E FULL STOP)開頭,緊接完全吻合網域名稱之字串。

XN-Label: From RFC 5890: “The class of labels that begin with the prefix "xn--" (case independent), but otherwise conform to the rules for LDH labels.”

XN-Label:節錄自 RFC 5890:「以前綴『"xn--"』(不分大小寫)開頭,且其餘部分遵循 LDH 標籤規則之一類標籤。」