3.2.2.4 已翻譯 對應原文版本:2.3.0

網域授權或控管權之驗證

跳至原文

Validation of Domain Authorization or Control

Prior to 2026-11-15, the CA SHALL adhere to Section 3.2.2.4 (and its subsections) of these Requirements or Section 3.2.2.4 of Version 2.2.7 of the Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates. Effective 2026-11-15, the CA SHALL adhere to Section 3.2.2.4 of these Requirements.

於 2026-11-15 之前,CA 應(SHALL)遵守本文件第 3.2.2.4 節(及其各小節)或《公開信賴 TLS 伺服器憑證簽發與管理之基本要求》(Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates)第 2.2.7 版第 3.2.2.4 節。自 2026-11-15 起,CA 應(SHALL)遵守本文件第 3.2.2.4 節。

This section defines the permitted processes and procedures for validating the Applicant’s ownership or control of the domain.

本節定義憑證機構(Certification Authority,CA)驗證申請者(Applicant)的網域所有權或控管權之允許流程與程序。

The CA MUST follow this process when choosing the Authorization Domain Name (ADN) for validation of each applied-for FQDN or Wildcard Domain Name:

CA 替每一個所申請的完全吻合網域名稱(Fully-Qualified Domain Name,FQDN)或萬用網域名稱(Wildcard Domain Name)選擇用於網域驗證的經授權網域名稱(Authorization Domain Name,ADN)時,應(MUST)遵從下列流程:

  1. Initialize A to the applied-for FQDN or Wildcard Domain Name.
  2. Choose a validation method. If A is a Wildcard Domain Name, the CA MUST choose a validation method with a check in the Wildcard column below. If A is an Onion Domain Name, the CA MUST choose a validation method with a check in the Onion column below.
  3. If A is an FQDN:
    1. If the validation method has a check in the CNAME column below, the CA MAY replace A with the result of a DNS CNAME lookup of A. This step may be repeated.
    2. If the validation method has a check in the Prune column below and A is not equal to the Base Domain Name of A, the CA MAY replace A with the result of pruning the leftmost Domain Label from A. This step may be repeated.
  4. If A is a Wildcard Domain Name:
    1. Remove ”*.” from the left-most portion of A.
    2. If the validation method has a check in the Prune column below and A is not equal to the Base Domain Name of A, the CA MAY replace A with the result of pruning the leftmost Domain Label from A. This step may be repeated.
  5. Use A as the ADN.
  1. 將 A 設為所申請的 FQDN 或萬用網域名稱。
  2. 選擇一種驗證方法。若 A 為萬用網域名稱,CA 應(MUST)選擇下表「萬用網域(Wildcard)」欄中標示「✔」的驗證方法;若 A 為 Onion 網域名稱(Onion Domain Name),CA 應(MUST)選擇下表「Onion」欄中標示「✔」的驗證方法。
  3. 若 A 為 FQDN:
    1. 若該驗證方法於下表「CNAME」欄中標示「✔」,CA 得(MAY)將 A 替換為對 A 執行 DNS CNAME 查詢所得之結果。本步驟可重複執行。
    2. 若該驗證方法於下表「刪減(Prune)」欄中標示「✔」,且 A 不等於 A 的基礎網域名稱(Base Domain Name),CA 得(MAY)將 A 替換為自 A 刪除最左側網域標籤(Domain Label)後所得之結果。本步驟可重複執行。
  4. 若 A 為萬用網域名稱:
    1. 移除 A 最左端的「*.」。
    2. 若該驗證方法於下表「刪減(Prune)」欄中標示「✔」,且 A 不等於 A 的基礎網域名稱,CA 得(MAY)將 A 替換為自 A 刪除最左側網域標籤後所得之結果。本步驟可重複執行。
  5. 以 A 作為經授權網域名稱(ADN)。
MethodWildcardPruneCNAMEOnion
3.2.2.4.4 Constructed Email to Domain Contact✔✔✔-
3.2.2.4.7 DNS Change✔✔✔-
3.2.2.4.12 Validating Applicant as a Domain Contact✔✔--
3.2.2.4.13 Email to DNS CAA Contact✔✔✔-
3.2.2.4.14 Email to DNS TXT Contact✔✔✔-
3.2.2.4.16 Phone Contact with DNS TXT Record Phone Contact✔✔✔-
3.2.2.4.17 Phone Contact with DNS CAA Phone Contact✔✔✔-
3.2.2.4.18 Agreed-Upon Change to Website v2---✔
3.2.2.4.19 Agreed-Upon Change to Website - ACME---✔
3.2.2.4.20 TLS Using ALPN---✔
3.2.2.4.21 DNS Labeled with Account ID - ACME✔✔--
3.2.2.4.22 DNS TXT Record with Persistent Value✔✔--
Appendix B.2.b✔✔-✔
驗證方法萬用網域(Wildcard)刪減(Prune)CNAMEOnion
3.2.2.4.4 使用特定格式的地址寄送電子郵件給網域名稱聯絡人✔✔✔-
3.2.2.4.7 DNS 變更✔✔✔-
3.2.2.4.12 驗證申請者為網域名稱聯絡人✔✔--
3.2.2.4.13 寄送電子郵件至 DNS CAA 聯絡人地址✔✔✔-
3.2.2.4.14 寄送電子郵件至 DNS TXT 聯絡人地址✔✔✔-
3.2.2.4.16 與 DNS TXT 紀錄電話聯絡人進行電話聯絡✔✔✔-
3.2.2.4.17 與 DNS CAA 電話聯絡人進行電話聯絡✔✔✔-
3.2.2.4.18 經約定之網站變更 v2---✔
3.2.2.4.19 經約定之網站變更 - ACME---✔
3.2.2.4.20 使用 ALPN 的 TLS 連線---✔
3.2.2.4.21 標記 Account ID 之 DNS - ACME✔✔--
3.2.2.4.22 具持久性紀錄值之 DNS TXT 紀錄✔✔--
附錄 B.2.b✔✔-✔

When the ADN is an Onion Domain Name, the CA SHALL validate it in accordance with Appendix B.

當經授權網域名稱(ADN)為 Onion 網域名稱時,CA 應(SHALL)依據附錄 B 進行網域驗證。

Completed validations of Applicant authority may be valid for the issuance of multiple Certificates over time. In all cases, the validation must have been initiated within the time period specified in the relevant requirement (such as Section 4.2.1 of this document) prior to Certificate issuance. For purposes of domain validation, the term Applicant includes the Applicant’s Parent Company, Subsidiary Company, or Affiliate.

已完成之申請者授權驗證,可於一段時間內對多次憑證簽發有效。不論何種情形,該驗證流程必須在憑證核發前,於相關要求(例如本文件的第 4.2.1 節)所定之期限內發起。就網域驗證(Domain Validation)而言,「申請者」一詞包含申請者的母公司(Parent Company)、子公司(Subsidiary Company)或關係企業(Affiliate)。

DNSSEC validation MUST be performed in accordance with Section 4.2.2.2 on all DNS queries associated with the validation of domain authorization or control, and CAA record lookups by the Primary Network Perspective.

由主要網路視角(Primary Network Perspective)執行之網域授權或控管權驗證相關的所有 DNS 查詢,以及 CAA 紀錄檢查,應(MUST)依據第 4.2.2.2 節執行 DNSSEC 驗證。

DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective, including CNAME lookups performed while choosing the ADN. The DNS resolver used for all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective MUST:

由主要網路視角執行之網域授權或控管權驗證相關的所有 DNS 查詢(包括選擇經授權網域名稱(ADN)過程中所執行之 CNAME 查詢),應(MUST)執行信賴鏈串鏈至 IANA DNSSEC 信賴根源(IANA DNSSEC root trust anchor)的 DNSSEC 驗證。主要網路視角用於網域授權或控管權驗證相關的所有 DNS 查詢之 DNS 解析器(DNS resolver)應(MUST):

  • support NSEC3 as defined in RFC 5155; and

For e-mail Domain Validation methods described in sections 3.2.2.4.4, 3.2.2.4.13, 3.2.2.4.14, DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS CNAME, CAA, TXT queries attempting to obtain the Authorization Domain Name associated with the validation of domain authorization or control by the Primary Network Perspective and CAs MUST NOT use local policy to disable DNSSEC validation. For all other DNS queries, DNSSEC validation back to the IANA DNSSEC root trust anchor SHOULD be performed and CAs SHOULD NOT use local policy to disable DNSSEC validation.

對於第 3.2.2.4.4 節、第 3.2.2.4.13 節、第 3.2.2.4.14 節中描述的電子郵件(e-mail)網域驗證方法,針對由主要網路視角(Primary Network Perspective)試圖取得與網域授權或控管權驗證相關之經授權網域名稱(Authorization Domain Name)的所有 DNS CNAME、CAA、TXT 查詢,應(MUST)執行信賴鏈串鏈至 IANA DNSSEC 信賴根源(IANA DNSSEC root trust anchor)的 DNSSEC 驗證,且 CA 不得(MUST NOT)利用內部政策停用 DNSSEC 驗證。對於其他所有 DNS 查詢,宜(SHOULD)執行信賴鏈串鏈至 IANA DNSSEC 信賴根源(IANA DNSSEC root trust anchor)的 DNSSEC 驗證,且 CA 不宜(SHOULD NOT)利用內部政策停用 DNSSEC 驗證。

For all other Domain Validation methods, DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective and CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.

對於其他所有的網域驗證方法,由主要網路視角(Primary Network Perspective)進行之與網域授權或控管權驗證相關的所有 DNS 查詢,應(MUST)執行信賴鏈串鏈至 IANA DNSSEC 信賴根源(IANA DNSSEC root trust anchor)的 DNSSEC 驗證,且 CA 不得(MUST NOT)在任何網域授權或控管權驗證相關的 DNS 查詢上利用內部政策停用 DNSSEC 驗證。

DNSSEC validation back to the IANA DNSSEC root trust anchor is considered outside the scope of self-audits performed to fulfill the requirements in Section 8.7.

信賴鏈串鏈至 IANA DNSSEC 信賴根源的 DNSSEC 驗證,被視為不屬於為符合第 8.7 節要求而執行之內部稽核(self-audits)的範圍。

DNSSEC validation back to the IANA DNSSEC root trust anchor is considered outside the scope of the logging requirements of Section 5.4.1.

信賴鏈串鏈至 IANA DNSSEC 信賴根源的 DNSSEC 驗證,被視為不屬於第 5.4.1 節紀錄要求(logging requirements)的範圍。

Note: FQDNs may be listed in Subscriber Certificates using dNSNames in the subjectAltName extension or in Subordinate CA Certificates via dNSNames in permittedSubtrees within the Name Constraints extension.

註:FQDN 可透過 subjectAltName 擴充欄位中之 dNSName 列在用戶憑證(Subscriber Certificates)中,或透過 Name Constraints 擴充欄位中之 permittedSubtrees 的 dNSName 列在下屬憑證機構憑證(Subordinate CA Certificates)中。