6.2.6 已翻譯 對應原文版本:2.3.0

私密金鑰匯入密碼模組或自密碼模組匯出

跳至原文

Private key transfer into or from a cryptographic module

If the Issuing CA generated the Private Key on behalf of the Subordinate CA, then the Issuing CA SHALL encrypt the Private Key for transport to the Subordinate CA. If the Issuing CA becomes aware that a Subordinate CA’s Private Key has been communicated to an unauthorized person or an organization not affiliated with the Subordinate CA, then the Issuing CA SHALL revoke all certificates that include the Public Key corresponding to the communicated Private Key.

若簽發憑證機構(Issuing CA)代表下屬憑證機構(Subordinate CA)產製私密金鑰,則簽發憑證機構應(SHALL)為了將其傳送至下屬憑證機構,而加密該私密金鑰。若簽發憑證機構獲悉下屬憑證機構之私密金鑰已提供予未經授權之人員,或提供予與下屬憑證機構無關聯之組織,則簽發憑證機構應(SHALL)廢止所有包含與該已提供私密金鑰相對應之公開金鑰的憑證。