交互認證之下屬憑證機構(Cross-Certified Subordinate CA)之擴充欄位
Cross-Certified Subordinate CA Extensions
Extension Presence Critical Description authorityKeyIdentifierMUST N See Section 7.1.2.11.1 basicConstraintsMUST Y See Section 7.1.2.10.4 certificatePoliciesMUST N See Section 7.1.2.2.6 crlDistributionPointsMUST N See Section 7.1.2.11.2 keyUsageMUST Y See Section 7.1.2.10.7 subjectKeyIdentifierMUST N See Section 7.1.2.11.4 authorityInformationAccessSHOULD N See Section 7.1.2.10.3 nameConstraintsMAY *1 See Section 7.1.2.10.8 Signed Certificate Timestamp List MAY N See Section 7.1.2.11.3 Any other extension NOT RECOMMENDED - See Section 7.1.2.11.5
| 擴充欄位 | 必要性 | 關鍵性 | 說明 |
|---|---|---|---|
authorityKeyIdentifier | 應(MUST) | N | 參見第 7.1.2.11.1 節 |
basicConstraints | 應(MUST) | Y | 參見第 7.1.2.10.4 節 |
certificatePolicies | 應(MUST) | N | 參見第 7.1.2.2.6 節 |
crlDistributionPoints | 應(MUST) | N | 參見第 7.1.2.11.2 節 |
keyUsage | 應(MUST) | Y | 參見第 7.1.2.10.7 節 |
subjectKeyIdentifier | 應(MUST) | N | 參見第 7.1.2.11.4 節 |
authorityInformationAccess | 宜(SHOULD) | N | 參見第 7.1.2.10.3 節 |
nameConstraints | 得(MAY) | *1 | 參見第 7.1.2.10.8 節 |
| Signed Certificate Timestamp(SCT)清單 | 得(MAY) | N | 參見第 7.1.2.11.3 節 |
| 任何其他擴充欄位 | 不建議(NOT RECOMMENDED) | - | 參見第 7.1.2.11.5 節 |
In addition to the above,
extKeyUsageextension requirements vary based on the relationship between the Issuer and Subject organizations represented in the Cross-Certificate.
除上述規定外,extKeyUsage 擴充欄位之要求,視交互憑證的簽發者與主體組織的關係而異。
The
extKeyUsageextension MAY be “unrestricted” as described in the following table if:
若符合以下條件,extKeyUsage 擴充欄位得(MAY)依下表所述設為「不受限制」:
- the
organizationNamerepresented in the Issuer and Subject names of the corresponding certificate are either:
- the same, or
- the
organizationNamerepresented in the Subject name is an affiliate of theorganizationNamerepresented in the Issuer name- the corresponding CA represented by the Subject of the Cross-Certificate is operated by the same organization as the Issuing CA or an Affiliate of the Issuing CA organization.
- 交互憑證的簽發者與主體名稱中的
organizationName符合下列任一情形:- 兩者相同,或
- 主體名稱中的
organizationName為簽發者名稱中的organizationName之關係企業
- 交互憑證之主體 CA,係由簽發憑證機構(Issuing CA)所屬組織或其關係企業負責營運。
Cross-Certified Subordinate CA with Unrestricted EKU Extension Presence Critical Description extKeyUsageSHOULD2 N See Section 7.1.2.2.4
| 擴充欄位 | 必要性 | 關鍵性 | 說明 |
|---|---|---|---|
extKeyUsage | 宜(SHOULD)2 | N | 參見第 7.1.2.2.4 節 |
In all other cases, the
extKeyUsageextension MUST be “restricted” as described in the following table:
在所有其他情況下,extKeyUsage 擴充欄位應(MUST)依下表所述設為「受限制」:
Cross-Certified Subordinate CA with Restricted EKU Extension Presence Critical Description extKeyUsageMUST2 N See Section 7.1.2.2.5
| 擴充欄位 | 必要性 | 關鍵性 | 說明 |
|---|---|---|---|
extKeyUsage | 應(MUST)2 | N | 參見第 7.1.2.2.5 節 |
註腳
-
See Section 7.1.2.10.8 for further requirements, including regarding criticality of this extension. ↩
-
有關此擴充欄位之進一步要求,包括是否標記為關鍵(critical)的相關要求,參見第 7.1.2.10.8 節。 ↩
-
While RFC 5280, Section 4.2.1.12 notes that this extension will generally only appear within end-entity certificates, these Requirements make use of this extension to further protect relying parties by limiting the scope of CA Certificates, as implemented by a number of Application Software Suppliers. ↩ ↩2
-
雖然 RFC 5280 第 4.2.1.12 節 指出,此擴充欄位通常僅出現於終端個體憑證,但本文件利用此擴充欄位以限制 CA 憑證(根憑證除外)的適用範圍;藉由此種限制,可進一步保護信賴憑證者(Relying Party),且此做法已由多家應用軟體供應商實作。 ↩ ↩2