7.1.2.10.2 已翻譯 對應原文版本:2.3.0

憑證機構(CA)憑證之填名(Naming)

跳至原文

CA Certificate Naming

All subject names MUST be encoded as specified in Section 7.1.4.

所有 subject 名稱應(MUST)依第 7.1.4 節規定之方式編碼。

The following table details the acceptable AttributeTypes that may appear within the type field of an AttributeTypeAndValue, as well as the contents permitted within the value field.

下表列出 AttributeTypeAndValue 之 type 欄位允許使用的 AttributeType,以及對應之 value 欄位允許填列的內容。

Attribute NamePresenceValueVerification
countryNameMUSTThe two-letter ISO 3166-1 country code for the country in which the CA’s place of business is located.Section 3.2.2.3
stateOrProvinceNameMAYIf present, the CA’s state or province information.Section 3.2.2.1
localityNameMAYIf present, the CA’s locality.Section 3.2.2.1
postalCodeMAYIf present, the CA’s zip or postal information.Section 3.2.2.1
streetAddressMAYIf present, the CA’s street address. Multiple instances MAY be present.Section 3.2.2.1
organizationNameMUSTThe CA’s name or DBA. The CA MAY include information in this field that differs slightly from the verified name, such as common variations or abbreviations, provided that the CA documents the difference and any abbreviations used are locally accepted abbreviations; e.g. if the official record shows “Company Name Incorporated”, the CA MAY use “Company Name Inc.” or “Company Name”.Section 3.2.2.2
organizationalUnitNameThis attribute MUST NOT be included in Root CA Certificates defined in Section 7.1.2.1 or TLS Subordinate CA Certificates defined in Section 7.1.2.5 or Technically-Constrained TLS Subordinate CA Certificates defined in Section 7.1.2.6. This attribute SHOULD NOT be included in other types of CA Certificates.--
commonNameMUSTThe contents SHOULD be an identifier for the certificate such that the certificate’s Name is unique across all certificates issued by the issuing certificate.
Any other attributeNOT RECOMMENDED-See Section 7.1.4.4
AttributeType 屬性名稱必要性value驗證方法
countryName應(MUST)為 CA 營業所在地國家之兩字母 ISO 3166-1 國家代碼。第 3.2.2.3 節
stateOrProvinceName得(MAY)若存在,為 CA 營業所在地之州或省份資訊。第 3.2.2.1 節
localityName得(MAY)若存在,為 CA 營業所在地之縣市地區資訊。第 3.2.2.1 節
postalCode得(MAY)若存在,為 CA 營業所在地之郵遞區號資訊。第 3.2.2.1 節
streetAddress得(MAY)若存在,為 CA 營業所在地之街道地址資訊。得(MAY)包含多個實體地址。第 3.2.2.1 節
organizationName應(MUST)為 CA 之名稱或商業名稱(DBA)。CA 得(MAY)在此欄位包含與已驗證名稱略有出入之資訊,例如常見之變體或縮寫,前提是 CA 須以書面文件記錄其差異及所使用之縮寫為當地公認之縮寫;例如:若官方記錄顯示為「Company Name Incorporated」,CA 得(MAY)使用「Company Name Inc.」或「Company Name」。第 3.2.2.2 節
organizationalUnitName第 7.1.2.1 節所定義之根憑證機構憑證、第 7.1.2.5 節所定義之 TLS 下屬憑證機構憑證,或第 7.1.2.6 節所定義之受技術約束之 TLS 下屬憑證機構憑證不得(MUST NOT)包含此屬性。其他類型之 CA 憑證不宜(SHOULD NOT)包含此屬性。--
commonName應(MUST)其內容宜(SHOULD)作為該憑證之識別資訊,以確保該憑證 Name 在同一簽發者所簽發之所有憑證中具有唯一性。
任何其他屬性不建議(NOT RECOMMENDED)-參見第 7.1.4.4 節