7.1.2.11.5 已翻譯 對應原文版本:2.3.0
其他擴充欄位
Other Extensions
All extensions and extension values not directly addressed by the applicable certificate profile:
所有適用之憑證剖繪未直接規範的擴充欄位及擴充欄位值:
- MUST apply in the context of the public Internet, unless:
- the extension OID falls within an OID arc for which the Applicant demonstrates ownership, or,
- the Applicant can otherwise demonstrate the right to assert the data in a public context.
- MUST NOT include semantics that will mislead the Relying Party about certificate information verified by the CA (such as including an extension that indicates a Private Key is stored on a smart card, where the CA is not able to verify that the corresponding Private Key is confined to such hardware due to remote issuance).
- MUST be DER encoded according to the relevant ASN.1 module defining the extension and extension values.
- 應(MUST)適用於公共網際網路,除非:
- 擴充欄位 OID 位於申請者能證明擁有其所有權之 OID arc 範圍內,或
- 申請者能以其他方式證明其有權於公共網際網路中聲明該資料。
- 不得(MUST NOT)具有可能使信賴憑證者對 CA 所驗證之憑證資訊產生誤解的含義(例如,憑證包含表示私密金鑰儲存於智慧卡之擴充欄位,而 CA 因採行遠端簽發,無法驗證對應之私密金鑰是否確實僅存在於該硬體內)。
- 應(MUST)依相關 ASN.1 模組中對該擴充欄位及擴充欄位值之定義,以 DER 編碼。
CAs SHALL NOT include additional extensions or values unless the CA is aware of a reason for including the data in the Certificate.
CA 不得(SHALL NOT)包含額外擴充欄位或欄位值,除非 CA 知悉有正當理由於憑證中包含該資料。