3.2.2.4.19 已翻譯 對應原文版本:2.3.0

經約定之網站變更 - ACME

跳至原文

Agreed-Upon Change to Website - ACME

Confirming the Applicant’s control over the ADN using the ACME HTTP Challenge method defined in RFC 8555, Section 8.3. The following are additive requirements to RFC 8555.

透過使用 RFC 8555 第 8.3 節 所定義的 ACME HTTP 挑戰(Challenge)方法,以確認申請者(Applicant)對經授權網域名稱(Authorization Domain Name,ADN)的控管權。除 RFC 8555 所規定之要求外,尚應符合下列額外要求。

The CA MUST receive a successful HTTP response from the request (meaning a 2xx HTTP status code must be received).

憑證機構(Certification Authority,CA)應(MUST)從該請求收到成功的 HTTP 回應(意即必須收到 2xx HTTP 狀態碼)。

The token (as defined in RFC 8555, Section 8.3) MUST NOT be used for more than 30 days from its creation. The CPS MAY specify a shorter validity period for Random Values, in which case the CA MUST follow its CPS.

Token(如 RFC 8555 第 8.3 節 所定義)自建立之日起,不得(MUST NOT)使用超過 30 日。憑證實務作業基準(Certification Practice Statement,CPS)得(MAY)規定更短的隨機值有效期限,在此情況下,CA 應(MUST)遵從其憑證實務作業基準(CPS)。

If the CA follows redirects, the following apply:

  1. Redirects MUST be initiated at the HTTP protocol layer. Redirects MUST be the result of a 301, 302, or 307 HTTP status code response, as defined in RFC 7231, Section 6.4, or a 308 HTTP status code response, as defined in RFC 7538, Section 3. Redirects MUST be to the final value of the Location HTTP response header, as defined in RFC 7231, Section 7.1.2.
  2. Redirects MUST be to resource URLs with either the “http” or “https” scheme.
  3. Redirects MUST be to resource URLs accessed via Authorized Ports.

若 CA 接受並遵從重新導向(redirects),則必須符合以下規定:

  1. 重新導向應(MUST)於 HTTP 協定層發起。重新導向應(MUST)由狀態碼為 RFC 7231 第 6.4 節 所定義之 301、302 或 307,或 RFC 7538 第 3 節 所定義之 308 的 HTTP 回應所觸發。重新導向的目標應(MUST)為 RFC 7231 第 7.1.2 節 所定義之 HTTP 回應標頭 Location 的最終值。
  2. 重新導向應(MUST)導向具有 “http” 或 “https” 協定的資源 URL 網址。
  3. 重新導向應(MUST)導向經由授權連接埠(Authorized Ports)存取的資源 URL 網址。

Except for Onion Domain Names, CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same challenge information (i.e. token) as the Primary Network Perspective.

除 Onion 網域名稱(Onion Domain Names)外,使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的挑戰資訊(即 ACME 使用的 Token)。