3.2.2.4.20 已翻譯 對應原文版本:2.3.0

使用 ALPN 的 TLS 連線

跳至原文

TLS Using ALPN

Confirming the Applicant’s control over the ADN by negotiating a new application layer protocol using the TLS Application-Layer Protocol Negotiation (ALPN) Extension RFC 7301 as defined in RFC 8737. The following are additive requirements to RFC 8737.

透過使用 RFC 7301 定義的 TLS Application-Layer Protocol Negotiation(ALPN)擴充功能(Extension),並依 RFC 8737 所定義之程序協商一個新的應用層協定,以確認申請者(Applicant)對經授權網域名稱(Authorization Domain Name,ADN)的控管權。除 RFC 8737 所規定之要求外,尚應符合下列額外要求。

The token (as defined in RFC 8737, Section 3) MUST NOT be used for more than 30 days from its creation. The CPS MAY specify a shorter validity period for the token, in which case the CA MUST follow its CPS.

Token(如 RFC 8737 第 3 節 所定義)自建立之日起,不得(MUST NOT)使用超過 30 日。憑證實務作業基準(Certification Practice Statement,CPS)得(MAY)規定更短的隨機值有效期限,在此情況下,CA 應(MUST)遵從其憑證實務作業基準(CPS)。

Except for Onion Domain Names, CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same challenge information (i.e. token) as the Primary Network Perspective.

除 Onion 網域名稱(Onion Domain Names)外,使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的挑戰資訊(即 ACME 使用的 Token)。