經約定之網站變更
Agreed-Upon Change to Website
Confirming the Applicant’s control over the requested IP Address by confirming the presence of a Request Token or Random Value contained in the content of a file or webpage in the form of a meta tag under the “/.well-known/pki-validation” directory, or another path registered with IANA for the purpose of validating control of IP Addresses, on the IP Address that is accessible by the CA via HTTP/HTTPS over an Authorized Port. The Request Token or Random Value MUST NOT appear in the request.
確認憑證機構(Certification Authority,CA)可透過 HTTP/HTTPS 在授權連接埠(Authorized Port)存取 IP 位址(IP Address)上的特定檔案或網頁,檢查內容是否存在以 HTML <meta> 標籤包含的請求符記(Request Token)或隨機值(Random Value),以確認申請者(Applicant)對所請求 IP 位址的控管權。該檔案或網頁必須位於「/.well-known/pki-validation」目錄下,或者用以驗證 IP 位址控管權而由 IANA 登記的其他路徑。請求符記或隨機值不得(MUST NOT)出現在請求 IP 的驗證路徑中。
If a Random Value is used, the CA SHALL provide a Random Value unique to the certificate request and SHALL not use the Random Value after the longer of:
若使用隨機值,CA 應(SHALL)提供該憑證申請唯一的隨機值,且在以下最長期限後不得(SHALL NOT)再使用該隨機值:
- 30 days or
- if the Applicant submitted the certificate request, the time frame permitted for reuse of validated information relevant to the certificate (such as in Section 4.2.1 of this document).
- 30 日;或
- 若申請者主動送出憑證申請,則期限為可重複使用與憑證相關之已驗證資料的時間允許範圍(例如本文件第 4.2.1 節所載)。
CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same challenge information (i.e. Random Value or Request Token) as the Primary Network Perspective.
使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的挑戰資訊(即隨機值或請求符記)。