4.9.9 已翻譯 對應原文版本:2.3.0

線上憑證廢止與狀態檢查之可用性

跳至原文

On-line revocation/status checking availability

The validity interval of an OCSP response is the difference in time between the thisUpdate and nextUpdate field, inclusive. For purposes of computing differences, a difference of 3,600 seconds shall be equal to one hour, and a difference of 86,400 seconds shall be equal to one day, ignoring leap-seconds.

線上憑證狀態協定(Online Certificate Status Protocol,OCSP)回應之效期區間為 thisUpdate 與 nextUpdate 欄位間之時間差(包含 thisUpdate 與 nextUpdate)。計算時間差的時候,3,600 秒應視為 1 小時,86,400 秒應視為 1 日,不考慮閏秒。

A certificate serial is “assigned” if:

憑證序號符合下列情形之一者,視為「已分配(assigned)」:

  • a Certificate or Precertificate with that serial number has been issued by the Issuing CA; or
  • 具有該序號之憑證或預簽憑證(Precertificate)已由簽發憑證機構(Issuing CA)簽發;或
  • a Precertificate with that serial number has been issued by a Precertificate Signing Certificate, as defined in Section 7.1.2.4, associated with the Issuing CA.
  • 具有該序號之預簽憑證已由簽發憑證機構(Issuing CA)關聯之預簽憑證簽章憑證(Precertificate Signing Certificate,如第 7.1.2.4 節所定義)簽發。

A certificate serial is “unassigned” if it is not “assigned”.

憑證序號若非屬「已分配」,則視為「未分配(unassigned)」。

The following SHALL apply for communicating the status of Certificates and Precertificates which include an Authority Information Access extension with an id-ad-ocsp accessMethod.

對於包含 accessMethod 為 id-ad-ocsp 之憑證機構資訊存取(Authority Information Access, AIA)擴充欄位的憑證及預簽憑證(Precertificate),其狀態資訊之提供應(SHALL)符合以下規定。

OCSP responders operated by the CA SHALL support the HTTP GET method, as described in RFC 6960 and/or RFC 5019. The CA MAY process the Nonce extension (1.3.6.1.5.5.7.48.1.2) in accordance with RFC 8954.

由 CA 營運之 OCSP 回應伺服器(OCSP Responder)應(SHALL)支援 HTTP GET 方法,如 RFC 6960 及/或 RFC 5019 所述。CA 得(MAY)依 RFC 8954 處理 Nonce 擴充欄位(1.3.6.1.5.5.7.48.1.2)。

For the status of a Subscriber Certificate or its corresponding Precertificate:

關於用戶憑證或其對應預簽憑證之狀態:

  • Effective 2025-01-15, an authoritative OCSP response MUST be available (i.e. the responder MUST NOT respond with the “unknown” status) starting no more than 15 minutes after the Certificate or Precertificate is first published or otherwise made available.
  • 自 2025-01-15 起,權威性 OCSP 回應應(MUST)自憑證或預簽憑證首次發布或以其他方式提供後,不超過 15 分鐘即可取得(即回應伺服器不得(MUST NOT)回覆「unknown」狀態)。
  • For OCSP responses with validity intervals less than sixteen hours, the CA SHALL provide an updated OCSP response prior to one-half of the validity period before the nextUpdate.
  • 對於效期區間不足 16 小時之 OCSP 回應,CA 應(SHALL)於距離 nextUpdate 尚有半個效期區間的時間前,提供已更新之 OCSP 回應。
  • For OCSP responses with validity intervals greater than or equal to sixteen hours, the CA SHALL provide an updated OCSP response at least eight hours prior to the nextUpdate, and no later than four days after the thisUpdate.
  • 對於效期區間不低於 16 小時之 OCSP 回應,CA 應(SHALL)至少於 nextUpdate 前 8 小時提供已更新之 OCSP 回應,且不得晚於 thisUpdate 後 4 日。

For the status of a Subordinate CA Certificate, the CA SHALL provide an updated OCSP response at least every twelve months, and within 24 hours after revoking the Certificate.

關於下屬憑證機構憑證(Subordinate CA Certificate)之狀態,CA 應(SHALL)至少每 12 個月提供一次已更新之 OCSP 回應,並應於廢止該憑證後 24 小時內提供已更新之 OCSP 回應。

The following SHALL apply for communicating the status of all Certificates for which an OCSP responder is willing or required to respond.

對於 OCSP 回應伺服器願意或必須回覆之所有憑證,其狀態資訊之提供應(SHALL)符合下列規定。

OCSP responses MUST conform to RFC 6960 and/or RFC 5019. OCSP responses MUST either:

OCSP 回應應(MUST)符合 RFC 6960 及/或 RFC 5019。OCSP 回應應(MUST)符合下列任一情況:

  1. be signed by the CA that issued the Certificates whose revocation status is being checked, or
  1. 由簽發其廢止狀態接受查詢之憑證的 CA 簽章 OCSP 回應;或
  1. be signed by an OCSP Responder which complies with the OCSP Responder Certificate Profile in Section 7.1.2.8.
  1. 由遵循第 7.1.2.8 節 OCSP 回應伺服器憑證剖繪之 OCSP 回應伺服器簽章 OCSP 回應。

OCSP responses for Subscriber Certificates MUST have a validity interval greater than or equal to eight hours and less than or equal to ten days.

用戶憑證之 OCSP 回應,其效期區間應(MUST)不低於 8 小時且不超過 10 日。

If the OCSP responder receives a request for the status of a certificate serial number that is “unassigned”, then the responder SHOULD NOT respond with a “good” status. If the OCSP responder is for a CA that is not Technically Constrained in line with Section 7.1.2.3 or Section 7.1.2.5, the responder MUST NOT respond with a “good” status for such requests.

若 OCSP 回應伺服器收到的查詢屬於「未分配」憑證序號狀態的請求,則回應伺服器不宜(SHOULD NOT)以「good」狀態回覆。若該 OCSP 回應伺服器所屬之 CA 並未依第 7.1.2.3 節或第 7.1.2.5 節受技術約束(Technically Constrained),則回應伺服器對此類請求不得(MUST NOT)以「good」狀態回覆。