憑證廢止請求之程序
Procedure for revocation request
The CA SHALL provide a process for Subscribers to request revocation of their own Certificates. The process MUST be described in the CA’s Certificate Policy or Certification Practice Statement. The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests and Certificate Problem Reports.
憑證機構(Certification Authority,CA)應(SHALL)提供用戶(Subscriber)請求廢止其自身憑證(Certificate)之流程。該流程應(MUST)於 CA 的憑證政策(Certificate Policy,CP)或憑證實務作業基準(Certification Practice Statement,CPS)中說明。CA 應(SHALL)持續維持每週 7 天、每天 24 小時(24x7)接受並處理廢止請求與憑證問題報告(Certificate Problem Report)之能力。
The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS.
CA 應(SHALL)向用戶、信賴憑證者(Relying Party)、應用軟體供應商(Application Software Supplier)及其他第三方提供明確的指示,以供回報疑似私密金鑰遭破解(Private Key Compromise)、憑證誤用(Certificate misuse),或其他類型之詐欺、遭破解、誤用、不當行為,或任何其他與憑證相關之事項。CA 應(SHALL)透過易於取得之線上方式及其憑證實務作業基準(CPS)第 1.5.2 節中公開揭露該等指示。