7.1.2.10.7 已翻譯 對應原文版本:2.3.0
憑證機構(CA)憑證之憑證金鑰用途(Key Usage)
CA Certificate Key Usage
Key Usage Permitted Required digitalSignatureY N1 nonRepudiationN — keyEnciphermentN — dataEnciphermentN — keyAgreementN — keyCertSignY Y cRLSignY Y encipherOnlyN — decipherOnlyN —
| 憑證金鑰用途(Key Usage) | 可否設定 | 設定必要性 |
|---|---|---|
digitalSignature | Y | N1 |
nonRepudiation | N | — |
keyEncipherment | N | — |
dataEncipherment | N | — |
keyAgreement | N | — |
keyCertSign | Y | Y |
cRLSign | Y | Y |
encipherOnly | N | — |
decipherOnly | N | — |
註腳
-
If a CA Certificate does not assert the
digitalSignaturebit, the CA Private Key MUST NOT be used to sign an OCSP Response. See Section 7.3 for more information. ↩ -
若 CA 憑證未設定
digitalSignature旗標位元,CA 私密金鑰不得(MUST NOT)用於簽章 OCSP 回應。更多資訊詳見第 7.3 節。 ↩