7.1.2.2.5 已翻譯 對應原文版本:2.3.0

交互認證之下屬憑證機構(Cross-Certified Subordinate CA)之擴充金鑰使用方法(Extended Key Usage)-受限制(Restricted)

跳至原文

Cross-Certified Subordinate CA Extended Key Usage - Restricted

Restricted TLS Cross-Certified Subordinate CA Extended Key Usage Purposes (i.e., for restricted Cross-Certified Subordinate CAs issuing TLS certificates directly or transitively).

受限制 TLS 交互認證之下屬憑證機構(Restricted TLS Cross-Certified Subordinate CA)之擴充金鑰使用方法適用目的(即適用於直接或間接簽發 TLS 憑證的受限制交互認證之下屬憑證機構)。

TLS Cross-Certified Subordinate CA EKU
Key PurposeDescription
id-kp-serverAuthMUST be present.
id-kp-clientAuthMAY be present.
id-kp-emailProtectionMUST NOT be present.
id-kp-codeSigningMUST NOT be present.
id-kp-timeStampingMUST NOT be present.
anyExtendedKeyUsageMUST NOT be present.
Any other valueNOT RECOMMENDED.
TLS 交互認證之下屬憑證機構 extKeyUsage(EKU)
金鑰適用目的(Key Purpose)說明
id-kp-serverAuth應(MUST)存在
id-kp-clientAuth得(MAY)存在
id-kp-emailProtection不得(MUST NOT)存在
id-kp-codeSigning不得(MUST NOT)存在
id-kp-timeStamping不得(MUST NOT)存在
anyExtendedKeyUsage不得(MUST NOT)存在
任何其他值不建議(NOT RECOMMENDED)

Restricted Non-TLS Cross-Certified Subordinate CA Extended Key Usage Purposes (i.e., for restricted Cross-Certified Subordinate CAs not issuing TLS certificates directly or transitively).

受限制非 TLS 交互認證之下屬憑證機構(Restricted Non-TLS Cross-Certified Subordinate CA)之擴充金鑰使用方法適用目的(即適用於不直接或不間接簽發 TLS 憑證的受限制交互認證之下屬憑證機構)。

Non-TLS Cross-Certified Subordinate CA EKU
Key PurposeDescription
id-kp-serverAuthMUST NOT be present.
anyExtendedKeyUsageMUST NOT be present.
Any other valueMAY be present.
非 TLS 交互認證之下屬憑證機構 extKeyUsage(EKU)
金鑰適用目的(Key Purpose)說明
id-kp-serverAuth不得(MUST NOT)存在
anyExtendedKeyUsage不得(MUST NOT)存在
任何其他值得(MAY)存在

Each included Extended Key Usage key usage purpose:

每項被包含的擴充金鑰使用方法之適用目的:

  1. MUST apply in the context of the public Internet (e.g. MUST NOT be for a service that is only valid in a privately managed network), unless:
    1. the key usage purpose falls within an OID arc for which the Applicant demonstrates ownership; or,
    2. the Applicant can otherwise demonstrate the right to assert the key usage purpose in a public context.
  2. MUST NOT include semantics that will mislead the Relying Party about the certificate information verified by the CA, such as including a key usage purpose asserting storage on a smart card, where the CA is not able to verify that the corresponding Private Key is confined to such hardware due to remote issuance.
  3. MUST be verified by the Issuing CA (i.e. the Issuing CA MUST verify the Cross-Certified Subordinate CA is authorized to assert the key usage purpose).
  1. 應(MUST)適用於公共網際網路(例如不得(MUST NOT)僅適用於私有管理網路中的服務),除非:
    1. 金鑰使用方法之適用目的位於申請者能證明擁有其所有權之 OID arc 範圍內;或
    2. 申請者能以其他方式證明其有權於公共網際網路中聲明該金鑰使用方法之適用目的。
  2. 不得(MUST NOT)具有可能使信賴憑證者對 CA 所驗證之憑證資訊產生誤解的含義,例如宣稱私密金鑰儲存於智慧卡的金鑰使用方法之適用目的,而 CA 因採行遠端簽發,無法驗證對應之私密金鑰是否確實僅存在於該硬體內。
  3. 應(MUST)由簽發憑證機構(Issuing CA)驗證(即簽發憑證機構應(MUST)驗證交互認證之下屬憑證機構是否經授權得主張該金鑰使用方法之適用目的)。

CAs MUST NOT include additional key usage purposes unless the CA is aware of a reason for including the key usage purpose in the Certificate.

CA 不得(MUST NOT)包含額外的金鑰使用方法之適用目的,除非 CA 知悉有正當理由於憑證中包含該金鑰使用方法之適用目的。