交互認證之下屬憑證機構(Cross-Certified Subordinate CA)憑證之憑證原則(Certificate Policies)
Cross-Certified Subordinate CA Certificate Certificate Policies
The Certificate Policies extension MUST contain at least one
PolicyInformation. EachPolicyInformationMUST match the following profile:
憑證原則(Certificate Policies)擴充欄位應(MUST)包含至少一個 PolicyInformation。每個 PolicyInformation 應(MUST)符合下列剖繪:
No Policy Restrictions (Affiliated CA) Field Presence Contents policyIdentifierMUST When the Issuing CA wishes to express that there are no policy restrictions, and if the Subordinate CA is an Affiliate of the Issuing CA, then the Issuing CA MAY use the anyPolicyPolicy Identifier, which MUST be the onlyPolicyInformationvalue.anyPolicyMUST policyQualifiersNOT RECOMMENDED If present, MUST contain only permitted policyQualifiersfrom the table below.
| 欄位 | 必要性 | 內容 |
|---|---|---|
policyIdentifier | 應(MUST) | 當簽發憑證機構(Issuing CA)欲表示不存在何政策限制,且下屬憑證機構(Subordinate CA)為其關係企業時,簽發憑證機構得(MAY)使用 anyPolicy 政策識別碼;此時,憑證原則擴充欄位中應(MUST)僅包含此一 PolicyInformation 值。 |
anyPolicy | 應(MUST) | |
policyQualifiers | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)僅包含下表所列之允許 policyQualifiers。 |
Policy Restricted Field Presence Contents policyIdentifierMUST One of the following policy identifiers: A Reserved Certificate Policy Identifier MUST The CA MUST include at least one Reserved Certificate Policy Identifier (see Section 7.1.6.1) associated with the given Subscriber Certificate type (see Section 7.1.2.7.1) transitively issued by this Certificate. anyPolicyMUST NOT The anyPolicyPolicy Identifier MUST NOT be present.Any other identifier MAY If present, MUST be defined by the CA and documented by the CA in its Certificate Policy and/or Certification Practice Statement. policyQualifiersNOT RECOMMENDED If present, MUST contain only permitted policyQualifiersfrom the table below.
| 欄位 | 必要性 | 內容 |
|---|---|---|
policyIdentifier | 應(MUST) | 下列政策識別碼之一: |
| 保留憑證政策識別碼 | 應(MUST) | CA 應(MUST)至少包含一個保留憑證政策識別碼(參見第 7.1.6.1 節),以對應由本憑證所代表之 CA 透過下屬 CA 間接簽發之指定用戶憑證類型(參見第 7.1.2.7.1 節)。 |
anyPolicy | 不得(MUST NOT) | anyPolicy 政策識別碼不得(MUST NOT)存在。 |
| 任何其他識別碼 | 得(MAY) | 若存在,應(MUST)由 CA 定義,並載明於其憑證政策(CP)及/或憑證實務作業基準(CPS)中。 |
policyQualifiers | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)僅包含下表所列之允許 policyQualifiers。 |
This Profile RECOMMENDS that the first
PolicyInformationvalue within the Certificate Policies extension contains the Reserved Certificate Policy Identifier (see 7.1.6.1)1. Regardless of the order ofPolicyInformationvalues, the Certificate Policies extension MUST include at least one Reserved Certificate Policy Identifier. If any Subscriber Certificates will chain up directly to the Certificate issued under this Certificate Profile, this Cross-Certified Subordinate CA Certificate MUST contain exactly one Reserved Certificate Policy Identifier.
本剖繪建議(RECOMMENDED)憑證原則擴充欄位中之第一個 PolicyInformation 值包含保留憑證政策識別碼(參見第 7.1.6.1 節)1。無論 PolicyInformation 值之順序為何,憑證原則擴充欄位應(MUST)至少包含一個保留憑證政策識別碼。若有任何用戶憑證直接串鏈至依本憑證剖繪所簽發之憑證,則本交互認證之下屬憑證機構憑證應(MUST)包含僅有一個保留憑證政策識別碼。
Note:
policyQualifiersis NOT RECOMMENDED to be present in any Certificate issued under this Certificate Profile because this information increases the size of the Certificate without providing any value to a typical Relying Party, and the information may be obtained by other means when necessary.
注意:本憑證剖繪所簽發之任何憑證均不建議(NOT RECOMMENDED)包含 policyQualifiers,因為此資訊會增加憑證大小,但對一般信賴憑證者並無實質價值,且於必要時可透過其他方式取得。
If the
policyQualifiersis permitted and present within aPolicyInformationfield, it MUST be formatted as follows:
若允許使用 policyQualifiers,且其存在於 PolicyInformation 欄位中,應(MUST)依下列格式編排:
Permitted policyQualifiersQualifier ID Presence Field Type Contents id-qt-cps(OID: 1.3.6.1.5.5.7.2.1)MAY IA5StringThe HTTP or HTTPS URL for the Issuing CA’s Certificate Policies, Certification Practice Statement, Relying Party Agreement, or other pointer to online policy information provided by the Issuing CA. Any other qualifier MUST NOT - -
| Qualifier ID | 必要性 | 欄位型別 | 內容 |
|---|---|---|---|
id-qt-cps(OID:1.3.6.1.5.5.7.2.1) | 得(MAY) | IA5String | 簽發憑證機構(Issuing CA)之憑證政策(CP)、憑證實務作業基準(CPS)、信賴憑證者協議(Relying Party Agreement),或其他由簽發憑證機構提供的線上政策資訊之 HTTP 或 HTTPS URL。 |
| 任何其他 qualifier | 不得(MUST NOT) | - | - |
註腳
-
Although RFC 5280 allows
PolicyInformations to appear in any order, several client implementations have implemented logic that considers thepolicyIdentifierthat matches a given filter. As such, ensuring the Reserved Certificate Policy Identifier is the firstPolicyInformationreduces the risk of interoperability challenges. ↩ -
雖然 RFC 5280 允許
PolicyInformation以任意順序出現,但部分用戶端實作所採用的程式邏輯會考量符合特定篩選條件的policyIdentifier。因此,確保含有保留憑證政策識別碼(Reserved Certificate Policy Identifier)之PolicyInformation位於首位,可降低發生交互運作問題之風險。 ↩