7.1.2.2 已翻譯 對應原文版本:2.3.0

交互認證之下屬憑證機構(Cross-Certified Subordinate CA)憑證剖繪

跳至原文

Cross-Certified Subordinate CA Certificate Profile

This Certificate Profile MAY be used when issuing a CA Certificate using the same Subject Name and Subject Public Key Information as one or more existing CA Certificate(s), whether a Root CA Certificate or Subordinate CA Certificate.

當簽發之 CA 憑證與一張或多張現有 CA 憑證(無論為根憑證機構(Root CA)憑證或下屬憑證機構(Subordinate CA)憑證)具有相同之主體名稱(Subject Name)及主體公開金鑰資訊(Subject Public Key Information)時,得(MAY)使用本憑證剖繪。

Before issuing a Cross-Certified Subordinate CA, the Issuing CA MUST confirm that the existing CA Certificate(s) are subject to these Baseline Requirements and were issued in compliance with the then-current version of the Baseline Requirements at time of issuance.

於簽發交互認證之下屬憑證機構(Cross-Certified Subordinate CA)憑證前,簽發憑證機構(Issuing CA)應(MUST)確認一張或多張既有 CA 憑證受本《基本要求》規範,且於簽發時係遵循當時有效版本之《基本要求》所簽發。

FieldDescription
tbsCertificate
versionMUST be v3(2)
serialNumberMUST be a non-sequential number greater than zero (0) and less than 2¹⁵⁹ containing at least 64 bits of output from a CSPRNG.
signatureSee Section 7.1.3.2
issuerMUST be byte-for-byte identical to the subject field of the Issuing CA. See Section 7.1.4.1
validitySee Section 7.1.2.2.1
subjectSee Section 7.1.2.2.2
subjectPublicKeyInfoSee Section 7.1.3.1
issuerUniqueIDMUST NOT be present
subjectUniqueIDMUST NOT be present
extensionsSee Section 7.1.2.2.3
signatureAlgorithmEncoded value MUST be byte-for-byte identical to the tbsCertificate.signature.
signature
欄位說明
tbsCertificate
version應(MUST)為 v3(2)
serialNumber應(MUST)為一個非連續之數值,其值大於 0 且小於 2¹⁵⁹,且其中至少 64 個位元應來自 CSPRNG 之輸出。
signature參見第 7.1.3.2 節
issuer應(MUST)與簽發憑證機構(Issuing CA)之 subject 欄位逐位元組完全相同。參見第 7.1.4.1 節
validity參見第 7.1.2.2.1 節
subject參見第 7.1.2.2.2 節
subjectPublicKeyInfo參見第 7.1.3.1 節
issuerUniqueID不得(MUST NOT)存在
subjectUniqueID不得(MUST NOT)存在
extensions參見第 7.1.2.2.3 節
signatureAlgorithm編碼後之值應(MUST)與 tbsCertificate.signature 逐位元組完全相同
signature