6.1.7 已翻譯 對應原文版本:2.3.0

憑證金鑰用途(比照 X.509 v3 `keyUsage` 欄位)

跳至原文

Key usage purposes (as per X.509 v3 key usage field)

Private Keys corresponding to Root Certificates MUST NOT be used to sign Certificates except in the following cases:

對應至根憑證(Root Certificate)的私密金鑰,不得(MUST NOT)用於簽章下列以外之任何憑證:

  1. Self-signed Certificates to represent the Root CA itself;
  1. 代表根憑證機構(Root CA)本身之自簽憑證;
  1. Certificates for Subordinate CAs and Cross-Certified Subordinate CA Certificates;
  1. 下屬憑證機構憑證(Subordinate CA Certificate)與交互認證之下屬憑證機構憑證(Cross-Certified Subordinate CA Certificate);
  1. Certificates for infrastructure purposes (administrative role certificates, internal CA operational device certificates); and
  1. 供基礎設施用途之憑證(例如行政角色憑證、CA 內部營運裝置憑證);以及
  1. Certificates for OCSP Response verification.
  1. 用於驗證 OCSP 回應之憑證。