7.1.2.11.5 已翻譯 對應原文版本:2.3.0

其他擴充欄位

跳至原文

Other Extensions

All extensions and extension values not directly addressed by the applicable certificate profile:

所有適用之憑證剖繪未直接規範的擴充欄位及擴充欄位值:

  1. MUST apply in the context of the public Internet, unless:
    1. the extension OID falls within an OID arc for which the Applicant demonstrates ownership, or,
    2. the Applicant can otherwise demonstrate the right to assert the data in a public context.
  2. MUST NOT include semantics that will mislead the Relying Party about certificate information verified by the CA (such as including an extension that indicates a Private Key is stored on a smart card, where the CA is not able to verify that the corresponding Private Key is confined to such hardware due to remote issuance).
  3. MUST be DER encoded according to the relevant ASN.1 module defining the extension and extension values.
  1. 應(MUST)適用於公共網際網路,除非:
    1. 擴充欄位 OID 位於申請者能證明擁有其所有權之 OID arc 範圍內,或
    2. 申請者能以其他方式證明其有權於公共網際網路中聲明該資料。
  2. 不得(MUST NOT)具有可能使信賴憑證者對 CA 所驗證之憑證資訊產生誤解的含義(例如,憑證包含表示私密金鑰儲存於智慧卡之擴充欄位,而 CA 因採行遠端簽發,無法驗證對應之私密金鑰是否確實僅存在於該硬體內)。
  3. 應(MUST)依相關 ASN.1 模組中對該擴充欄位及擴充欄位值之定義,以 DER 編碼。

CAs SHALL NOT include additional extensions or values unless the CA is aware of a reason for including the data in the Certificate.

CA 不得(SHALL NOT)包含額外擴充欄位或欄位值,除非 CA 知悉有正當理由於憑證中包含該資料。