多視角簽發佐證(Multi-Perspective Issuance Corroboration)
Multi-Perspective Issuance Corroboration
Multi-Perspective Issuance Corroboration attempts to corroborate the determinations (i.e., domain validation pass/fail, CAA permission/prohibition) made by the Primary Network Perspective from multiple remote Network Perspectives before Certificate issuance. This process can improve protection against equally-specific prefix Border Gateway Protocol (BGP) attacks or hijacks.
多視角簽發佐證(Multi-Perspective Issuance Corroboration)試圖在憑證簽發之前,從多個遠端網路視角(Remote Network Perspectives)佐證由主要網路視角(Primary Network Perspective)所做出的判定結果(即網域驗證通過/失敗、CAA 許可/禁止)。此流程可提升相同路由前綴長度(equally-specific prefix)之邊界閘道協定(Border Gateway Protocol,BGP)攻擊或劫持的防護能力。
The CA MAY use either the same set, or different sets of Network Perspectives when performing Multi-Perspective Issuance Corroboration for the required 1) Domain Authorization or Control and 2) CAA Record checks.
當針對所需之(1)網域授權或控管權驗證,及(2)CAA 紀錄檢查而執行多視角簽發佐證時,憑證機構(Certification Authority,CA)得(MAY)兩者都使用相同組合或不同組合之網路視角。
The set of responses from the relied upon Network Perspectives MUST provide the CA with the necessary information to allow it to affirmatively assess:
作為判定依據的網路視角回應集合應(MUST)向 CA 提供必要資訊,以允許其明確評估:
- the presence of the expected 1) Random Value, 2) Request Token, 3) IP Address, 4) Contact Address, or 5) Persistent DCV TXT Record, as required by the relied upon validation method specified in Section 3.2.2.4 and Section 3.2.2.5; and
- the CA’s authority to issue to the requested domain(s), as specified in Section 4.2.2.1.
- 是否存在預期之(1)隨機值(Random Value)、(2)請求符記(Request Token)、(3)IP 位址(IP Address)、(4)聯絡地址,或(5)持久性 DCV TXT 紀錄,如同採用第 3.2.2.4 節及第 3.2.2.5 節所列驗證方法之規定要求;以及
- CA 是否可依第 4.2.2.1 節規定獲得授權,對申請中的網域簽發憑證。
Section 3.2.2.4 and Section 3.2.2.5 describe the validation methods that require the use of Multi-Perspective Issuance Corroboration and how a Network Perspective can corroborate the outcomes determined by the Primary Network Perspective.
第 3.2.2.4 節與第 3.2.2.5 節說明哪些網域驗證方法須採用多視角簽發佐證,以及其他網路視角如何佐證由主要網路視角所做出的判定結果。
Results or information obtained from one Network Perspective MUST NOT be reused or cached when performing validation through subsequent Network Perspectives (e.g., different Network Perspectives cannot rely on a shared DNS cache to prevent an adversary with control of traffic from one Network Perspective from poisoning the DNS cache used by other Network Perspectives). The network infrastructure providing Internet connectivity to a Network Perspective MAY be administered by the same organization providing the computational services required to operate the Network Perspective. All communications between a remote Network Perspective and the CA MUST take place over an authenticated and encrypted channel relying on modern protocols (e.g., over HTTPS).
當接續使用其他網路視角進行驗證時,不得(MUST NOT)重複使用或快取(cache)任一網路視角所取得之結果或資訊(例如:不同的網路視角不得依賴共用的 DNS 快取,以避免控制其中一個網路視角流量之攻擊者,污染其他網路視角所使用的 DNS 快取)。為網路視角提供網際網路連線的網路基礎設施,得(MAY)由提供該網路視角運作所需運算服務之同一組織管理。遠端網路視角與 CA 之間的所有通訊應(MUST)透過採用現代協定(例如:透過 HTTPS)的經身分驗證且加密之通道進行。
A Network Perspective MAY use a recursive DNS resolver that is NOT co-located with the Network Perspective. However, the DNS resolver used by the Network Perspective MUST fall within the same Regional Internet Registry service region as the Network Perspective relying upon it. Furthermore, for any pair of DNS resolvers used on a Multi-Perspective Issuance Corroboration attempt, the straight-line distance between the two DNS resolvers MUST be at least 500 km. The location of a DNS resolver is determined by the point where unencapsulated outbound DNS queries are typically first handed off to the network infrastructure providing Internet connectivity to that DNS resolver.
網路視角得(MAY)使用未與該網路視角同地設置的遞迴 DNS 解析器。然而,該網路視角所使用的 DNS 解析器應(MUST)與使用該解析器的網路視角位於同一個區域網際網路註冊管理機構(Regional Internet Registry)的服務區域內。此外,在一次多視角簽發佐證執行中所使用的 DNS 解析器,任兩個 DNS 解析器之間的直線距離應(MUST)至少為 500 公里。DNS 解析器的位置,通常係指未封裝之對外 DNS 查詢首次交接給提供該 DNS 解析器網際網路連線之網路基礎設施的地點。
CAs MAY immediately retry Multi-Perspective Issuance Corroboration using the same validation method or an alternative method (e.g., a CA can immediately retry validation using “Email to DNS TXT Contact” if “Agreed-Upon Change to Website - ACME” does not corroborate the outcome of Multi-Perspective Issuance Corroboration). When retrying Multi-Perspective Issuance Corroboration, CAs MUST NOT rely on corroborations from previous attempts. There is no stipulation regarding the maximum number of validation attempts that may be performed in any period of time.
CA 得(MAY)立即使用相同的驗證方法或替代驗證方法重新執行多視角簽發佐證(例如:若「經約定之網站變更 - ACME」的多視角簽發佐證結果無法成立,CA 可立即使用「寄送電子郵件至 DNS TXT 聯絡人地址」重新執行驗證)。當重新執行多視角簽發佐證時,CA 不得(MUST NOT)依據先前取得之佐證資訊。對於任何期間內可執行的驗證次數上限,本文件不作規定。
The “Quorum Requirements” Table describes quorum requirements related to Multi-Perspective Issuance Corroboration. If the CA does NOT rely on the same set of Network Perspectives for both Domain Authorization or Control and CAA Record checks, the quorum requirements MUST be met for both sets of Network Perspectives (i.e.,the Domain Authorization or Control set and the CAA record check set). Network Perspectives are considered distinct when the straight-line distance between them is at least 500 km. Network Perspectives are considered “remote” when they are distinct from the Primary Network Perspective and the other Network Perspectives represented in a quorum.
「法定數量要求(Quorum Requirements)」表格列出多視角簽發佐證的法定數量(Quorum)要求。若 CA 在進行網域授權或控管權驗證與 CAA 紀錄檢查時,兩者均未採用相同組合之網路視角,則兩組網路視角(即網域授權或控管權驗證組與 CAA 紀錄檢查組)應(MUST)皆符合法定數量要求。當網路視角彼此間的直線距離至少為 500 公里時,被視為彼此相異(distinct)。當某一網路視角與主要網路視角,以及法定數量中的其他網路視角皆為相異時,該網路視角即視為「遠端」。
A CA MAY reuse corroborating evidence for CAA record quorum compliance for a maximum of 398 days. After issuing a Certificate to a domain, remote Network Perspectives MAY omit retrieving and processing CAA records for the same domain or its subdomains in subsequent Certificate requests from the same Applicant for up to a maximum of 398 days.
CA 得(MAY)重複使用 CAA 紀錄檢查符合法定數量要求的佐證證明,最長不超過 398 日。向某網域簽發憑證後,針對同一申請者之後續憑證申請,遠端網路視角得(MAY)省略取得及處理相同網域或其子網域的 CAA 紀錄,最長不超過 398 日。
Quorum Requirements # of Distinct Remote Network Perspectives Used # of Allowed non-Corroborations 2-5 1 6+ 2
| 相異的遠端網路視角數量 | 容許無效佐證的遠端網路視角數量 |
|---|---|
| 2-5 | 1 |
| 6+ | 2 |
Remote Network Perspectives performing Multi-Perspective Issuance Corroboration:
執行多視角簽發佐證的遠端網路視角:
MUST:
Network Hardening
- Rely upon networks (e.g., Internet Service Providers or Cloud Provider Networks) implementing measures to mitigate BGP routing incidents in the global Internet routing system for providing internet connectivity to the Network Perspective.
應(MUST):
-
網路強化(Network Hardening)
- 依賴已採取對應措施,可於全球網際網路路由系統中,降低受 BGP 路由事故影響之網路供應服務(例如:網際網路服務供應商或雲端服務供應商的網路),對該網路視角提供網際網路連線。
SHOULD:
Facility & Service Provider Requirements
- Be hosted from an ISO/IEC 27001 certified facility or equivalent security framework independently audited and certified or reported.
- Rely on services covered in one of the following reports: System and Organization Controls 2 (SOC 2), ISAE 3000, ENISA 715, FedRAMP Moderate, C5:2020, CSA STAR CCM, or equivalent services framework independently audited and certified or reported.
Vulnerability Detection and Patch Management
- Implement intrusion detection and prevention controls to protect against common network and system threats.
- Document and follow a vulnerability correction process that addresses the identification, review, response, and remediation of vulnerabilities.
- Undergo or perform a Vulnerability Scan at least every three (3) months.
- Undergo a Penetration Test on at least an annual basis.
- Apply recommended security patches within six (6) months of the security patch’s availability, unless the CA documents that the security patch would introduce additional vulnerabilities or instabilities that outweigh the benefits of applying the security patch.
System Hardening
- Disable all accounts, applications, services, protocols, and ports that are not used.
- Implement multi-factor authentication for all user accounts.
Network Hardening
- Configure each network boundary control (firewall, switch, router, gateway, or other network control device or system) with rules that support only the services, protocols, ports, and communications identified as necessary to its operations.
- Rely upon networks (e.g., Internet Service Providers) that: 1) use mechanisms based on Secure Inter-Domain Routing (RFC 6480), for example, BGP Prefix Origin Validation (RFC 6811), 2) make use of other non-RPKI route-leak prevention mechanisms (such as RFC 9234), and 3) apply current best practices described in BCP 194. While It is RECOMMENDED that under normal operating conditions Network Perspectives performing Multi-Perspective Issuance Corroboration forward all Internet traffic via a network or set of networks that filter RPKI-invalid BGP routes as defined by RFC 6811, it is NOT REQUIRED.
宜(SHOULD):
-
設施與服務供應商要求
- 託管於通過 ISO/IEC 27001 認證的設施,或經獨立稽核且通過認證或出具稽核報告之同等安全架構的設施。
- 依賴受下列任一稽核報告查核涵蓋之供應服務:System and Organization Controls 2(SOC 2)、ISAE 3000、ENISA 715、FedRAMP Moderate、C5:2020、CSA STAR CCM,或其他經獨立稽核且通過認證或出具稽核報告之同等服務架構。
-
弱點偵測與修補程式管理
- 實施入侵偵測與入侵防護控管措施,以防範常見的網路及系統威脅。
- 建立書面文件化的弱點修正流程並據以執行,該流程應涵蓋弱點之識別、審查、回應及修補。
- 至少每 3 個月接受或執行一次弱點掃描。
- 至少每年接受一次滲透測試。
- 於安全修補程式可取得後 6 個月內套用建議的安全修補程式,除非 CA 以書面文件記錄並說明,該安全修補程式會引入額外的弱點或不穩定性,且其風險大於套用該安全修補程式所帶來的效益。
-
系統強化(System Hardening)
- 停用所有未使用的帳號、應用程式、服務、通訊協定及連接埠。
- 對所有使用者帳號實施多因子身分驗證。
-
網路強化
- 對每個網路邊界控制(防火牆、交換器、路由器、閘道器或其他網路控制設備或系統)配置規則,使其僅允許經識別為其運作所需之服務、通訊協定、連接埠和通訊之流量通過。
- 依賴符合下列條件之網路供應服務(例如:網際網路服務供應商):(1)採用基於 Secure Inter-Domain Routing(SIDR,安全網域間路由;RFC 6480)安全架構的機制,例如 BGP 路由前綴來源驗證(BGP Prefix Origin Validation;RFC 6811),(2)採用其他非 RPKI 的路由洩漏防範機制(例如 RFC 9234),以及(3)導入 BCP 194 所述的當前最佳實務。此外,雖然建議(RECOMMENDED)在正常運作情況下,執行多視角簽發佐證的網路視角應透過一個或多個依 RFC 6811 規範,過濾經 RPKI 驗證為無效之 BGP 路由的網路來轉送所有網際網路流量,但這屬於非強制要求(NOT REQUIRED)。
Beyond the above considerations, computing systems performing Multi-Perspective Issuance Corroboration are considered outside of the audit scope described in Section 8 of these Requirements.
除以上要求外,執行多視角簽發佐證的運算系統,被視為不屬於本文件第 8 節所述之稽核範圍。
If any of the above considerations are performed by a Delegated Third Party, the CA MAY obtain reasonable evidence from the Delegated Third Party to ascertain assurance that one or more of the above considerations are followed. As an exception to Section 1.3.2, Delegated Third Parties are not required to be within the audit scope described in Section 8 of these Requirements to satisfy the above considerations.
若上述任何要求(considerations)是由受委任第三方(Delegated Third Party)執行,CA 得(MAY)自受委任第三方取得合理證明,以查明並確信上述一項或多項要求已獲得遵從。作為第 1.3.2 節之例外,受委任第三方無須為了符合上述各項要求,而納入本文件第 8 節所述之稽核範圍。
Phased Implementation Timeline:
分階段實施時程:
- Effective 2025-03-15, the CA MUST implement Multi-Perspective Issuance Corroboration using at least two (2) remote Network Perspectives. The CA MAY proceed with certificate issuance if the number of remote Network Perspectives that do not corroborate the determinations made by the Primary Network Perspective (“non-corroborations”) is greater than allowed in the Quorum Requirements table.
- 自 2025-03-15 起:CA 應(MUST)使用至少 2 個遠端網路視角進行多視角簽發佐證。若無法佐證主要網路視角所做判定的遠端網路視角數量(「無效佐證」)大於《法定數量要求表》所允許的數量,CA 得(MAY)繼續進行憑證簽發。
- Effective 2025-09-15, the CA MUST implement Multi-Perspective Issuance Corroboration using at least two (2) remote Network Perspectives. The CA MUST ensure that the requirements defined in Quorum Requirements Table are satisfied. If the requirements are not satisfied, then the CA MUST NOT proceed with issuance of the Certificate.
- 自 2025-09-15 起:CA 應(MUST)使用至少 2 個遠端網路視角進行多視角簽發佐證。CA 應(MUST)確保符合《法定數量要求表》所定義的要求。若未符合該等要求,則 CA 不得(MUST NOT)繼續簽發憑證。
- Effective 2026-03-15, the CA MUST implement Multi-Perspective Issuance Corroboration using at least three (3) remote Network Perspectives. The CA MUST ensure that the requirements defined in Quorum Requirements Table are satisfied, and the remote Network Perspectives that corroborate the Primary Network Perspective fall within the service regions of at least two (2) distinct Regional Internet Registries. If the requirements are not satisfied, then the CA MUST NOT proceed with issuance of the Certificate.
- 自 2026-03-15 起:CA 應(MUST)使用至少 3 個遠端網路視角進行多視角簽發佐證。CA 應(MUST)確保符合《法定數量要求表》所定義的要求,且佐證主要網路視角的遠端網路視角分別位於至少 2 個不同的區域網際網路註冊管理機構(Regional Internet Registries)服務區域內。若未符合該等要求,則 CA 不得(MUST NOT)繼續簽發憑證。
- Effective 2026-06-15, the CA MUST implement Multi-Perspective Issuance Corroboration using at least four (4) remote Network Perspectives. The CA MUST ensure that the requirements defined in Quorum Requirements Table are satisfied, and the remote Network Perspectives that corroborate the Primary Network Perspective fall within the service regions of at least two (2) distinct Regional Internet Registries. If the requirements are not satisfied, then the CA MUST NOT proceed with issuance of the Certificate.
- 自 2026-06-15 起:CA 應(MUST)使用至少 4 個遠端網路視角進行多視角簽發佐證。CA 應(MUST)確保符合《法定數量要求表》所定義的要求,且佐證主要網路視角的遠端網路視角分別位於至少 2 個不同的區域網際網路註冊管理機構(Regional Internet Registries)服務區域內。若未符合該等要求,則 CA 不得(MUST NOT)繼續簽發憑證。
- Effective 2026-12-15, the CA MUST implement Multi-Perspective Issuance Corroboration using at least five (5) remote Network Perspectives. The CA MUST ensure that the requirements defined in Quorum Requirements Table are satisfied, and the remote Network Perspectives that corroborate the Primary Network Perspective fall within the service regions of at least two (2) distinct Regional Internet Registries. If the requirements are not satisfied, then the CA MUST NOT proceed with issuance of the Certificate.
- 自 2026-12-15 起:CA 應(MUST)使用至少 5 個遠端網路視角進行多視角簽發佐證。CA 應(MUST)確保符合《法定數量要求表》所定義的要求,且佐證主要網路視角的遠端網路視角分別位於至少 2 個不同的區域網際網路註冊管理機構(Regional Internet Registries)服務區域內。若未符合該等要求,則 CA 不得(MUST NOT)繼續簽發憑證。