6.1.7 已翻譯 對應原文版本:2.3.0
憑證金鑰用途(比照 X.509 v3 `keyUsage` 欄位)
Key usage purposes (as per X.509 v3 key usage field)
Private Keys corresponding to Root Certificates MUST NOT be used to sign Certificates except in the following cases:
對應至根憑證(Root Certificate)的私密金鑰,不得(MUST NOT)用於簽章下列以外之任何憑證:
- Self-signed Certificates to represent the Root CA itself;
- 代表根憑證機構(Root CA)本身之自簽憑證;
- Certificates for Subordinate CAs and Cross-Certified Subordinate CA Certificates;
- 下屬憑證機構憑證(Subordinate CA Certificate)與交互認證之下屬憑證機構憑證(Cross-Certified Subordinate CA Certificate);
- Certificates for infrastructure purposes (administrative role certificates, internal CA operational device certificates); and
- 供基礎設施用途之憑證(例如行政角色憑證、CA 內部營運裝置憑證);以及
- Certificates for OCSP Response verification.
- 用於驗證 OCSP 回應之憑證。