4.9.1.1 已翻譯 對應原文版本:2.3.0

廢止用戶憑證之事由

跳至原文

Reasons for Revoking a Subscriber Certificate

The CA MAY support revocation of Short-lived Subscriber Certificates.

憑證機構(Certification Authority,CA)得(MAY)支援廢止短效期用戶憑證(Short-lived Subscriber Certificate)。

With the exception of Short-lived Subscriber Certificates, the CA SHALL revoke a Certificate within 24 hours and use the corresponding CRLReason (see Section 7.2.2) if one or more of the following occurs:

除短效期用戶憑證外,若發生下列一項或多項情形時,CA 應(SHALL)於 24 小時內廢止憑證,並使用對應之 CRLReason(參見第 7.2.2 節):

  1. The Subscriber requests in writing, without specifying a CRLreason, that the CA revoke the Certificate (CRLReason “unspecified (0)” which results in no reasonCode extension being provided in the CRL);
  1. 用戶以書面方式請求 CA 廢止憑證,且未指定 CRLReason(CRLReason 為「unspecified (0)」,因此憑證廢止清冊(Certificate Revocation List,CRL)中不會包含 reasonCode 擴充欄位);
  1. The Subscriber notifies the CA that the original certificate request was not authorized and does not retroactively grant authorization (CRLReason #9, privilegeWithdrawn);
  1. 用戶通知 CA,其原始憑證申請未經授權,且不溯及既往補予授權(CRLReason #9,privilegeWithdrawn);
  1. The CA obtains evidence that the Subscriber’s Private Key corresponding to the Public Key in the Certificate suffered a Key Compromise (CRLReason #1, keyCompromise);
  1. CA 取得證據,顯示用戶憑證中的公開金鑰(Public Key),其所對應之私密金鑰(Private Key)遭破解(Key Compromise)(CRLReason #1,keyCompromise);
  1. The CA is made aware of a demonstrated or proven method that can easily compute the Subscriber’s Private Key based on the Public Key in the Certificate, including but not limited to those identified in Section 6.1.1.3(5) (CRLReason #1, keyCompromise);
  1. CA 獲悉已有經展示或證實之方法,可依據憑證中的公開金鑰輕易計算出與其對應之用戶私密金鑰,包括但不限於第 6.1.1.3(5) 節中所列之方法(CRLReason #1,keyCompromise);
  1. The CA obtains evidence that the validation of domain authorization or control for any Fully-Qualified Domain Name or IP address in the Certificate should not be relied upon, including cases where the CA failed to perform CAA checking correctly or where issuance was not permitted according to Section 3.2.2.8 (CAA Records) (CRLReason #4, superseded).
  1. CA 取得證據,顯示憑證中任何完全吻合網域名稱(Fully-Qualified Domain Name,FQDN)或 IP 位址(IP Address)之網域授權或控管權驗證結果不可被信賴,包括 CA 未正確執行 CAA 檢查,或依第 3.2.2.8 節(CAA Records)之規定不被許可簽發該憑證之情況(CRLReason #4,superseded)。

With the exception of Short-lived Subscriber Certificates, the CA SHOULD revoke a certificate within 24 hours and MUST revoke a Certificate within 5 days and use the corresponding CRLReason (see Section 7.2.2) if one or more of the following occurs:

除短效期用戶憑證外,若發生下列一項或多項情形時,CA 宜(SHOULD)於 24 小時內廢止憑證,且最遲應(MUST)於 5 日內完成廢止,並使用對應之 CRLReason(參見第 7.2.2 節):

  1. The Certificate no longer complies with the requirements of Section 6.1.5 and Section 6.1.6 (CRLReason #4, superseded);
  1. 該憑證已不再遵循第 6.1.5 節與第 6.1.6 節之規定(CRLReason #4,superseded);
  1. The CA obtains evidence that the Certificate was misused (CRLReason #9, privilegeWithdrawn);
  1. CA 取得證據,顯示憑證遭誤用(CRLReason #9,privilegeWithdrawn);
  1. The CA is made aware that a Subscriber has violated one or more of its material obligations under the Subscriber Agreement or Terms of Use (CRLReason #9, privilegeWithdrawn);
  1. CA 獲悉用戶違反其依用戶協議(Subscriber Agreement)或使用條款(Terms of Use)所負之一項或多項重大義務(CRLReason #9,privilegeWithdrawn);
  1. The CA is made aware of any circumstance indicating that use of a Fully-Qualified Domain Name or IP address in the Certificate is no longer legally permitted (e.g. a court or arbitrator has revoked a Domain Name Registrant’s right to use the Domain Name) (CRLReason #5, cessationOfOperation);
  1. CA 獲悉任何足以顯示憑證中所載之完全吻合網域名稱(FQDN)或 IP 位址已不再依法得以使用之情況(例如:法院或仲裁人已撤銷網域名稱註冊人使用該網域名稱之權利)(CRLReason #5,cessationOfOperation);
  1. The CA is made aware that a Wildcard Certificate has been used to authenticate a fraudulently misleading subordinate Fully-Qualified Domain Name (CRLReason #9, privilegeWithdrawn);
  1. CA 獲悉某張萬用網域憑證(Wildcard Certificate)已被用於驗證具有詐欺性誤導之該萬用網域 FQDN 的子網域(Subordinate FQDN)網站(CRLReason #9,privilegeWithdrawn);
  1. The CA is made aware of a material change in the information contained in the Certificate (CRLReason #9, privilegeWithdrawn);
  1. CA 獲悉憑證所載之資訊發生重大變更(CRLReason #9,privilegeWithdrawn);
  1. The CA is made aware that the Certificate was not issued in accordance with these Requirements or the CA’s Certificate Policy or Certification Practice Statement (CRLReason #4, superseded);
  1. CA 獲悉該憑證未依據本文件要求規定、CA 的憑證政策(Certificate Policy,CP)或憑證實務作業基準(Certification Practice Statement,CPS)(CRLReason #4,superseded)簽發;
  1. The CA determines or is made aware that any of the information appearing in the Certificate is inaccurate (CRLReason #9, privilegeWithdrawn);
  1. CA 判定或獲悉憑證所載之任何資訊有誤(CRLReason #9,privilegeWithdrawn);
  1. The CA’s right to issue Certificates under these Requirements expires or is revoked or terminated, unless the CA has made arrangements to continue maintaining the CRL/OCSP Repository (CRLReason “unspecified (0)” which results in no reasonCode extension being provided in the CRL);
  1. CA 依《基本要求》簽發憑證之權利到期、遭撤銷或終止,除非 CA 已作好安排以持續維護 CRL/OCSP 儲存庫(CRLReason 為「unspecified (0)」,因此 CRL 中不會包含 reasonCode 擴充欄位);
  1. Revocation is required by the CA’s Certificate Policy and/or Certification Practice Statement for a reason that is not otherwise required to be specified by this section 4.9.1.1 (CRLReason “unspecified (0)” which results in no reasonCode extension being provided in the CRL); or
  1. 依 CA 的憑證政策(CP)及/或憑證實務作業基準(CPS),因本文件第 4.9.1.1 節未另行規定之原因而必須廢止憑證(CRLReason 為「unspecified (0)」,因此 CRL 中不會包含 reasonCode 擴充欄位);或
  1. The CA is made aware of a demonstrated or proven method that exposes the Subscriber’s Private Key to compromise or if there is clear evidence that the specific method used to generate the Private Key was flawed (CRLReason #1, keyCompromise).
  1. CA 獲悉已有經展示或證實之方法,足以導致用戶的私密金鑰遭破解,或有明確證據顯示用於產製該私密金鑰之特定方法存在缺陷(CRLReason #1,keyCompromise)。