7.1.2.2.6 已翻譯 對應原文版本:2.3.0

交互認證之下屬憑證機構(Cross-Certified Subordinate CA)憑證之憑證原則(Certificate Policies)

跳至原文

Cross-Certified Subordinate CA Certificate Certificate Policies

The Certificate Policies extension MUST contain at least one PolicyInformation. Each PolicyInformation MUST match the following profile:

憑證原則(Certificate Policies)擴充欄位應(MUST)包含至少一個 PolicyInformation。每個 PolicyInformation 應(MUST)符合下列剖繪:

No Policy Restrictions (Affiliated CA)
FieldPresenceContents
policyIdentifierMUSTWhen the Issuing CA wishes to express that there are no policy restrictions, and if the Subordinate CA is an Affiliate of the Issuing CA, then the Issuing CA MAY use the anyPolicy Policy Identifier, which MUST be the only PolicyInformation value.
anyPolicyMUST
policyQualifiersNOT RECOMMENDEDIf present, MUST contain only permitted policyQualifiers from the table below.
無政策限制(適用於關係企業 CA)
欄位必要性內容
policyIdentifier應(MUST)當簽發憑證機構(Issuing CA)欲表示不存在何政策限制,且下屬憑證機構(Subordinate CA)為其關係企業時,簽發憑證機構得(MAY)使用 anyPolicy 政策識別碼;此時,憑證原則擴充欄位中應(MUST)僅包含此一 PolicyInformation 值。
anyPolicy應(MUST)
policyQualifiers不建議(NOT RECOMMENDED)若存在,應(MUST)僅包含下表所列之允許 policyQualifiers。
Policy Restricted
FieldPresenceContents
policyIdentifierMUSTOne of the following policy identifiers:
A Reserved Certificate Policy IdentifierMUSTThe CA MUST include at least one Reserved Certificate Policy Identifier (see Section 7.1.6.1) associated with the given Subscriber Certificate type (see Section 7.1.2.7.1) transitively issued by this Certificate.
anyPolicyMUST NOTThe anyPolicy Policy Identifier MUST NOT be present.
Any other identifierMAYIf present, MUST be defined by the CA and documented by the CA in its Certificate Policy and/or Certification Practice Statement.
policyQualifiersNOT RECOMMENDEDIf present, MUST contain only permitted policyQualifiers from the table below.
受政策限制
欄位必要性內容
policyIdentifier應(MUST)下列政策識別碼之一:
保留憑證政策識別碼應(MUST)CA 應(MUST)至少包含一個保留憑證政策識別碼(參見第 7.1.6.1 節),以對應由本憑證所代表之 CA 透過下屬 CA 間接簽發之指定用戶憑證類型(參見第 7.1.2.7.1 節)。
anyPolicy不得(MUST NOT)anyPolicy 政策識別碼不得(MUST NOT)存在。
任何其他識別碼得(MAY)若存在,應(MUST)由 CA 定義,並載明於其憑證政策(CP)及/或憑證實務作業基準(CPS)中。
policyQualifiers不建議(NOT RECOMMENDED)若存在,應(MUST)僅包含下表所列之允許 policyQualifiers。

This Profile RECOMMENDS that the first PolicyInformation value within the Certificate Policies extension contains the Reserved Certificate Policy Identifier (see 7.1.6.1)1. Regardless of the order of PolicyInformation values, the Certificate Policies extension MUST include at least one Reserved Certificate Policy Identifier. If any Subscriber Certificates will chain up directly to the Certificate issued under this Certificate Profile, this Cross-Certified Subordinate CA Certificate MUST contain exactly one Reserved Certificate Policy Identifier.

本剖繪建議(RECOMMENDED)憑證原則擴充欄位中之第一個 PolicyInformation 值包含保留憑證政策識別碼(參見第 7.1.6.1 節)1。無論 PolicyInformation 值之順序為何,憑證原則擴充欄位應(MUST)至少包含一個保留憑證政策識別碼。若有任何用戶憑證直接串鏈至依本憑證剖繪所簽發之憑證,則本交互認證之下屬憑證機構憑證應(MUST)包含僅有一個保留憑證政策識別碼。

Note: policyQualifiers is NOT RECOMMENDED to be present in any Certificate issued under this Certificate Profile because this information increases the size of the Certificate without providing any value to a typical Relying Party, and the information may be obtained by other means when necessary.

注意:本憑證剖繪所簽發之任何憑證均不建議(NOT RECOMMENDED)包含 policyQualifiers,因為此資訊會增加憑證大小,但對一般信賴憑證者並無實質價值,且於必要時可透過其他方式取得。

If the policyQualifiers is permitted and present within a PolicyInformation field, it MUST be formatted as follows:

若允許使用 policyQualifiers,且其存在於 PolicyInformation 欄位中,應(MUST)依下列格式編排:

Permitted policyQualifiers
Qualifier IDPresenceField TypeContents
id-qt-cps (OID: 1.3.6.1.5.5.7.2.1)MAYIA5StringThe HTTP or HTTPS URL for the Issuing CA’s Certificate Policies, Certification Practice Statement, Relying Party Agreement, or other pointer to online policy information provided by the Issuing CA.
Any other qualifierMUST NOT--
允許之 policyQualifiers
Qualifier ID必要性欄位型別內容
id-qt-cps(OID:1.3.6.1.5.5.7.2.1)得(MAY)IA5String簽發憑證機構(Issuing CA)之憑證政策(CP)、憑證實務作業基準(CPS)、信賴憑證者協議(Relying Party Agreement),或其他由簽發憑證機構提供的線上政策資訊之 HTTP 或 HTTPS URL。
任何其他 qualifier不得(MUST NOT)--

註腳

  1. Although RFC 5280 allows PolicyInformations to appear in any order, several client implementations have implemented logic that considers the policyIdentifier that matches a given filter. As such, ensuring the Reserved Certificate Policy Identifier is the first PolicyInformation reduces the risk of interoperability challenges. ↩

  2. 雖然 RFC 5280 允許 PolicyInformation 以任意順序出現,但部分用戶端實作所採用的程式邏輯會考量符合特定篩選條件的 policyIdentifier。因此,確保含有保留憑證政策識別碼(Reserved Certificate Policy Identifier)之 PolicyInformation 位於首位,可降低發生交互運作問題之風險。 ↩