7.1.2.2.3 已翻譯 對應原文版本:2.3.0

交互認證之下屬憑證機構(Cross-Certified Subordinate CA)之擴充欄位

跳至原文

Cross-Certified Subordinate CA Extensions

ExtensionPresenceCriticalDescription
authorityKeyIdentifierMUSTNSee Section 7.1.2.11.1
basicConstraintsMUSTYSee Section 7.1.2.10.4
certificatePoliciesMUSTNSee Section 7.1.2.2.6
crlDistributionPointsMUSTNSee Section 7.1.2.11.2
keyUsageMUSTYSee Section 7.1.2.10.7
subjectKeyIdentifierMUSTNSee Section 7.1.2.11.4
authorityInformationAccessSHOULDNSee Section 7.1.2.10.3
nameConstraintsMAY*1See Section 7.1.2.10.8
Signed Certificate Timestamp ListMAYNSee Section 7.1.2.11.3
Any other extensionNOT RECOMMENDED-See Section 7.1.2.11.5
擴充欄位必要性關鍵性說明
authorityKeyIdentifier應(MUST)N參見第 7.1.2.11.1 節
basicConstraints應(MUST)Y參見第 7.1.2.10.4 節
certificatePolicies應(MUST)N參見第 7.1.2.2.6 節
crlDistributionPoints應(MUST)N參見第 7.1.2.11.2 節
keyUsage應(MUST)Y參見第 7.1.2.10.7 節
subjectKeyIdentifier應(MUST)N參見第 7.1.2.11.4 節
authorityInformationAccess宜(SHOULD)N參見第 7.1.2.10.3 節
nameConstraints得(MAY)*1參見第 7.1.2.10.8 節
Signed Certificate Timestamp(SCT)清單得(MAY)N參見第 7.1.2.11.3 節
任何其他擴充欄位不建議(NOT RECOMMENDED)-參見第 7.1.2.11.5 節

In addition to the above, extKeyUsage extension requirements vary based on the relationship between the Issuer and Subject organizations represented in the Cross-Certificate.

除上述規定外,extKeyUsage 擴充欄位之要求,視交互憑證的簽發者與主體組織的關係而異。

The extKeyUsage extension MAY be “unrestricted” as described in the following table if:

若符合以下條件,extKeyUsage 擴充欄位得(MAY)依下表所述設為「不受限制」:

  • the organizationName represented in the Issuer and Subject names of the corresponding certificate are either:
    • the same, or
    • the organizationName represented in the Subject name is an affiliate of the organizationName represented in the Issuer name
  • the corresponding CA represented by the Subject of the Cross-Certificate is operated by the same organization as the Issuing CA or an Affiliate of the Issuing CA organization.
  • 交互憑證的簽發者與主體名稱中的 organizationName 符合下列任一情形:
    • 兩者相同,或
    • 主體名稱中的 organizationName 為簽發者名稱中的 organizationName 之關係企業
  • 交互憑證之主體 CA,係由簽發憑證機構(Issuing CA)所屬組織或其關係企業負責營運。
Cross-Certified Subordinate CA with Unrestricted EKU
ExtensionPresenceCriticalDescription
extKeyUsageSHOULD2NSee Section 7.1.2.2.4
extKeyUsage(EKU)不受限制之交互認證之下屬憑證機構
擴充欄位必要性關鍵性說明
extKeyUsage宜(SHOULD)2N參見第 7.1.2.2.4 節

In all other cases, the extKeyUsage extension MUST be “restricted” as described in the following table:

在所有其他情況下,extKeyUsage 擴充欄位應(MUST)依下表所述設為「受限制」:

Cross-Certified Subordinate CA with Restricted EKU
ExtensionPresenceCriticalDescription
extKeyUsageMUST2NSee Section 7.1.2.2.5
extKeyUsage(EKU)受限制之交互認證之下屬憑證機構
擴充欄位必要性關鍵性說明
extKeyUsage應(MUST)2N參見第 7.1.2.2.5 節

註腳

  1. See Section 7.1.2.10.8 for further requirements, including regarding criticality of this extension. ↩

  2. 有關此擴充欄位之進一步要求,包括是否標記為關鍵(critical)的相關要求,參見第 7.1.2.10.8 節。 ↩

  3. While RFC 5280, Section 4.2.1.12 notes that this extension will generally only appear within end-entity certificates, these Requirements make use of this extension to further protect relying parties by limiting the scope of CA Certificates, as implemented by a number of Application Software Suppliers. ↩ ↩2

  4. 雖然 RFC 5280 第 4.2.1.12 節 指出,此擴充欄位通常僅出現於終端個體憑證,但本文件利用此擴充欄位以限制 CA 憑證(根憑證除外)的適用範圍;藉由此種限制,可進一步保護信賴憑證者(Relying Party),且此做法已由多家應用軟體供應商實作。 ↩ ↩2