資訊之公佈
Publication of information
The CA SHALL publicly disclose its Certificate Policy and/or Certification Practice Statement through an appropriate and readily accessible online means that is available on a 24x7 basis. The CA SHALL publicly disclose its CA business practices to the extent required by the CA’s selected audit scheme (see Section 8.4).
CA 應(SHALL)透過適當且易於存取的線上管道(online means),提供每週 7 天、每天 24 小時(24x7)之憑證政策(CP)及/或憑證實務作業基準(CPS)的公開揭露。CA 應(SHALL)於 CA 所選稽核架構(audit scheme)的要求範圍內,對外公開其 CA 業務作業基準(CA business practices)(參見第 8.4 節)。
The CA SHALL develop, implement, enforce, and at least once every 366 days update a Certificate Policy and/or Certification Practice Statement that describes in detail how the CA implements the latest version of these Requirements.
CA 應(SHALL)制定、實施、落實憑證政策(CP)及/或憑證實務作業基準(CPS),且至少每 366 日更新一次;其內容詳細描述 CA 如何實作最新版之本文件要求規定。
The Certificate Policy and/or Certification Practice Statement MUST be structured in accordance with RFC 3647 and MUST include all material required by RFC 3647.
憑證政策(CP)及/或憑證實務作業基準(CPS)應(MUST)依據 RFC 3647 規定之架構撰寫,且應(MUST)包含 RFC 3647 要求的所有內容。
The CA SHALL publicly give effect to these Requirements and represent that it will adhere to the latest published version. The CA MAY fulfill this requirement by incorporating these Requirements directly into its Certificate Policy and/or Certification Practice Statements or by incorporating them by reference using a clause such as the following (which MUST include a link to the official version of these Requirements):
CA 應(SHALL)公開實行(give effect to)本文件要求規定,並聲明(represent)其將遵守最新版本之規定。CA 得(MAY)將本文件要求規定直接納入(incorporating)其憑證政策(CP)及/或憑證實務作業基準(CPS),或採用如下之聲明條款以引用方式(by reference)納入其中以滿足要求(該條款應(MUST)包含本《基本要求》官方版本之連結):
[Name of CA] conforms to the current version of the Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates published at https://cabforum.org/baseline-requirements-documents/. In the event of any inconsistency between this document and those Requirements, those Requirements take precedence.
【CA名稱】遵循 https://www.cabforum.org 所發布之《公開信賴 TLS 伺服器憑證簽發與管理之基本要求》(Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates)之現行版本規定。若本文件與上述《基本要求》有任何不一致(inconsistency)之處,應優先適用(take precedence)《基本要求》之規定。
The CA SHALL host test Web pages that allow Application Software Suppliers to test their software with Subscriber Certificates that chain up to each publicly trusted Root Certificate. At a minimum, the CA SHALL host separate Web pages using Subscriber Certificates that are:
- valid,
- revoked, and
- expired.
CA 應(SHALL)架設測試網頁,以允許應用軟體供應商(Application Software Suppliers)使用憑證鏈串鏈至(chain up to)各自的公開信賴根憑證(Publicly Trusted Root Certificate)之用戶憑證來測試其軟體。CA 至少應(SHALL)架設使用下列狀態之用戶憑證的獨立網頁供測試:
- 有效(valid),
- 廢止(revoked),以及
- 過期(expired)。