執行識別與鑑別作業
Performing identification and authentication functions
The certificate request MAY include all factual information about the Applicant to be included in the Certificate, and such additional information as is necessary for the CA to obtain from the Applicant in order to comply with these Requirements and the CA’s Certificate Policy and/or Certification Practice Statement. In cases where the certificate request does not contain all the necessary information about the Applicant, the CA SHALL obtain the remaining information from the Applicant or, having obtained it from a reliable, independent, third-party data source, confirm it with the Applicant. The CA SHALL establish and follow a documented procedure for verifying all data requested for inclusion in the Certificate by the Applicant.
憑證申請得(MAY)包含擬記載於憑證中之所有與申請者(Applicant)相關的事實資料,以及憑證機構(Certification Authority,CA)為了遵循本文件要求規定及其憑證政策(Certificate Policy,CP)及/或憑證實務作業基準(Certification Practice Statement,CPS)而有必要向申請者取得之其他資訊。若憑證申請未包含全部所需的申請者資訊,CA 應(SHALL)向申請者取得其餘所需資訊,或先從可靠且獨立的第三方資料來源取得該資訊,再向申請者確認其內容。CA 應(SHALL)建立並遵從書面程序,以驗證申請者要求記載於憑證中的所有資料。
Applicant information MUST include, but not be limited to, at least one Fully-Qualified Domain Name or IP address to be included in the Certificate’s
subjectAltNameextension.
申請者資訊應(MUST)包括(但不限於)至少一個將記載於憑證 subjectAltName 擴充欄位中的完全吻合網域名稱(Fully-Qualified Domain Name,FQDN)或 IP 位址(IP Address)。
Section 6.3.2 limits the validity period of Subscriber Certificates.
第 6.3.2 節限制用戶憑證(Subscriber Certificates)的有效期。
The CA MAY use the documents and data provided in Section 3.2 to verify certificate information, or may reuse previous validations themselves, including validation of authority, provided that the CA obtained the data or document from a source specified under Section 3.2 or completed the validation itself within the maximum number of days prior to issuing the Certificate, as defined in the following table:
CA 得(MAY)使用第 3.2 節規定的文件與資料驗證憑證資訊,或重複使用先前已完成的驗證成果(包括組織授權之驗證),前提是 CA 簽發憑證前,應於下表所定之最大天數內,自第 3.2 節規定之來源取得資料或文件,或 CA 已完成的驗證成果:
Subject Identity Information validation data reuse periods Certificate issued on or after Certificate issued before Maximum data reuse period 2026-03-15 825 days 2026-03-15 398 days
| 憑證於此日或之後簽發 | 憑證於此日前簽發 | 可重複使用已驗證資料之最長期限 |
|---|---|---|
| 2026-03-15 | 825 日 | |
| 2026-03-15 | 398 日 |
For validation of Domain Names and IP Addresses according to Section 3.2.2.4 and Section 3.2.2.5, any data, document, or completed validation used MUST be obtained within the maximum number of days prior to issuing the Certificate, as defined in the following table:
依第 3.2.2.4 節與第 3.2.2.5 節進行的網域名稱(Domain Name)及 IP 位址驗證,其所使用之任何資料、文件或完成的驗證成果,應(MUST)於簽發憑證前,於下表所定之最大天數內取得:
Domain Name and IP Address validation data reuse periods Certificate issued on or after Certificate issued before Maximum data reuse period 2026-03-15 398 days 2026-03-15 2027-03-15 200 days 2027-03-15 2029-03-15 100 days 2029-03-15 10 days
| 憑證於此日或之後簽發 | 憑證於此日前簽發 | 可重複使用已驗證資料之最大期限 |
|---|---|---|
| 2026-03-15 | 398 日 | |
| 2026-03-15 | 2027-03-15 | 200 日 |
| 2027-03-15 | 2029-03-15 | 100 日 |
| 2029-03-15 | 10 日 |
In no case may a prior validation be reused if any data or document used in the prior validation was obtained more than the maximum time permitted for reuse of the data or document prior to issuing the Certificate.
若先前驗證所使用之任何資料或文件,其取得日期於簽發憑證前已超過可重複使用已驗證資料之最長期限,則不得於任何情況下重複使用先前的已驗證成果。
After the change to any validation method specified in the Baseline Requirements or EV Guidelines, a CA may continue to reuse validation data or documents collected prior to the change, or the validation itself, for the period stated in Section 4.2.1 unless otherwise specifically provided in a ballot.
於《基本要求》或《EV 指引》所規定之任何驗證方法發生變更後,CA 可繼續重複使用變更前所蒐集的驗證資料或文件,或先前完成的已驗證成果,其可重複使用期限依第 4.2.1 節規定辦理;除非投票案(Ballot)另有明文規定。
The CA SHALL develop, maintain, and implement documented procedures that identify and require additional verification activity for High Risk Certificate Requests prior to the Certificate’s approval, as reasonably necessary to ensure that such requests are properly verified under these Requirements.
CA 應(SHALL)建立、維護並實施書面程序,以識別高風險憑證申請(High Risk Certificate Request),並於核准憑證前要求執行額外的驗證作業;該等程序應於合理且必要之範圍內,確保此類申請均依本文件要求規定完成妥善驗證。
If a Delegated Third Party fulfills any of the CA’s obligations under this section, the CA SHALL verify that the process used by the Delegated Third Party to identify and further verify High Risk Certificate Requests provides at least the same level of assurance as the CA’s own processes.
若受委任第三方(Delegated Third Party)履行 CA 於本節所規定之任何義務,CA 應(SHALL)確認受委任第三方用以識別及進一步驗證的高風險憑證申請之流程,其所提供的保證等級至少與 CA 自身流程相同。