7.1.2.1 已翻譯 對應原文版本:2.3.0
根憑證機構(Root CA)憑證剖繪
Root CA Certificate Profile
Field Description tbsCertificateversionMUST be v3(2) serialNumberMUST be a non-sequential number greater than zero (0) and less than 2¹⁵⁹ containing at least 64 bits of output from a CSPRNG. signatureSee Section 7.1.3.2 issuerEncoded value MUST be byte-for-byte identical to the encoded subjectvaliditySee Section 7.1.2.1.1 subjectSee Section 7.1.2.10.2 subjectPublicKeyInfoSee Section 7.1.3.1 issuerUniqueIDMUST NOT be present subjectUniqueIDMUST NOT be present extensionsSee Section 7.1.2.1.2 signatureAlgorithmEncoded value MUST be byte-for-byte identical to the tbsCertificate.signaturesignature
| 欄位 | 說明 |
|---|---|
tbsCertificate | |
version | 應(MUST)為 v3(2) |
serialNumber | 應(MUST)為一個非連續之數值,其值大於 0 且小於 2¹⁵⁹,且其中至少 64 個位元應來自 CSPRNG 之輸出。 |
signature | 參見第 7.1.3.2 節 |
issuer | 編碼後之值應(MUST)與編碼後的 subject 逐位元組完全相同。 |
validity | 參見第 7.1.2.1.1 節 |
subject | 參見第 7.1.2.10.2 節 |
subjectPublicKeyInfo | 參見第 7.1.3.1 節 |
issuerUniqueID | 不得(MUST NOT)存在 |
subjectUniqueID | 不得(MUST NOT)存在 |
extensions | 參見第 7.1.2.1.2 節 |
signatureAlgorithm | 編碼後之值應(MUST)與 tbsCertificate.signature 逐位元組完全相同 |
signature |