3.2.2.5.1 已翻譯 對應原文版本:2.3.0

經約定之網站變更

跳至原文

Agreed-Upon Change to Website

Confirming the Applicant’s control over the requested IP Address by confirming the presence of a Request Token or Random Value contained in the content of a file or webpage in the form of a meta tag under the “/.well-known/pki-validation” directory, or another path registered with IANA for the purpose of validating control of IP Addresses, on the IP Address that is accessible by the CA via HTTP/HTTPS over an Authorized Port. The Request Token or Random Value MUST NOT appear in the request.

確認憑證機構(Certification Authority,CA)可透過 HTTP/HTTPS 在授權連接埠(Authorized Port)存取 IP 位址(IP Address)上的特定檔案或網頁,檢查內容是否存在以 HTML <meta> 標籤包含的請求符記(Request Token)或隨機值(Random Value),以確認申請者(Applicant)對所請求 IP 位址的控管權。該檔案或網頁必須位於「/.well-known/pki-validation」目錄下,或者用以驗證 IP 位址控管權而由 IANA 登記的其他路徑。請求符記或隨機值不得(MUST NOT)出現在請求 IP 的驗證路徑中。

If a Random Value is used, the CA SHALL provide a Random Value unique to the certificate request and SHALL not use the Random Value after the longer of:

若使用隨機值,CA 應(SHALL)提供該憑證申請唯一的隨機值,且在以下最長期限後不得(SHALL NOT)再使用該隨機值:

  1. 30 days or
  2. if the Applicant submitted the certificate request, the time frame permitted for reuse of validated information relevant to the certificate (such as in Section 4.2.1 of this document).
  1. 30 日;或
  2. 若申請者主動送出憑證申請,則期限為可重複使用與憑證相關之已驗證資料的時間允許範圍(例如本文件第 4.2.1 節所載)。

CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same challenge information (i.e. Random Value or Request Token) as the Primary Network Perspective.

使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的挑戰資訊(即隨機值或請求符記)。