7.1.2.10.7 已翻譯 對應原文版本:2.3.0

憑證機構(CA)憑證之憑證金鑰用途(Key Usage)

跳至原文

CA Certificate Key Usage

Key UsagePermittedRequired
digitalSignatureYN1
nonRepudiationN—
keyEnciphermentN—
dataEnciphermentN—
keyAgreementN—
keyCertSignYY
cRLSignYY
encipherOnlyN—
decipherOnlyN—
憑證金鑰用途(Key Usage)可否設定設定必要性
digitalSignatureYN1
nonRepudiationN—
keyEnciphermentN—
dataEnciphermentN—
keyAgreementN—
keyCertSignYY
cRLSignYY
encipherOnlyN—
decipherOnlyN—

註腳

  1. If a CA Certificate does not assert the digitalSignature bit, the CA Private Key MUST NOT be used to sign an OCSP Response. See Section 7.3 for more information. ↩

  2. 若 CA 憑證未設定 digitalSignature 旗標位元,CA 私密金鑰不得(MUST NOT)用於簽章 OCSP 回應。更多資訊詳見第 7.3 節。 ↩