3.2.2.4.7 已翻譯 對應原文版本:2.3.0

DNS 變更

跳至原文

DNS Change

Confirming the Applicant’s control over the ADN by confirming the presence of a Random Value or Request Token in a DNS CNAME, TXT or CAA record returned in a query for either:

藉由檢查下列任一查詢所回傳的 DNS CNAME、TXT 或 CAA 紀錄中是否存在隨機值(Random Value)或請求符記(Request Token),以確認申請者(Applicant)對經授權網域名稱(Authorization Domain Name,ADN)的控管權:

  1. the ADN; or
  2. the ADN prefixed with a Domain Label that begins with an underscore character.
  1. 經授權網域名稱(ADN);或
  2. 在經授權網域名稱(ADN)前頭加上一個以底線字元(underscore character)開頭之網域標籤(Domain Label)。

If a Random Value is used, the CA SHALL provide a Random Value unique to the Certificate request and SHALL not use the Random Value after:

若使用隨機值,憑證機構(Certification Authority,CA)應(SHALL)提供該憑證申請唯一的隨機值,且在以下時間後不得(SHALL NOT)再使用該隨機值:

  1. 30 days; or
  2. if the Applicant submitted the Certificate request, the time frame permitted for reuse of validated information relevant to the Certificate (such as in Section 4.2.1 of these Guidelines or Section 3.2.2.14.3 of the EV Guidelines).
  1. 30 日;或
  2. 若申請者主動送出憑證申請,則期限為可重複使用與憑證相關之已驗證資料的時間允許範圍(例如本文件第 4.2.1 節或《EV 指引》第 3.2.2.14.3 節所載)。

CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same challenge information (i.e. Random Value or Request Token) as the Primary Network Perspective.

使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的挑戰資訊(即隨機值或請求符記)。

If the CA or an Affiliate of the CA operates a DNS zone to which Applicants can delegate (via CNAME) their underscore-prefixed Domain Label, the CA MUST ensure that each Applicant delegates to a unique FQDN within that zone. A CA or Affiliate of a CA SHOULD NOT operate such a service, and SHOULD direct any Applicants using such a service to use the method described in Section 3.2.2.4.22 instead.

若 CA 或其關係企業(Affiliate)營運一個 DNS 區域(zone),且申請者可將帶有底線開頭的網域標籤委託(透過 CNAME)至該區域,則 CA 應(MUST)確保每位申請者委託對象的 FQDN 為該 DNS 區域內唯一的 FQDN。CA 或其關係企業不宜(SHOULD NOT)營運此類服務,並宜(SHOULD)引導使用此類服務的申請者改用第 3.2.2.4.22 節所述之方法。