7.1.2.3.1 已翻譯 對應原文版本:2.3.0

受技術約束之非 TLS 下屬憑證機構(Technically Constrained Non-TLS Subordinate CA)之擴充欄位

跳至原文

Technically Constrained Non-TLS Subordinate CA Extensions

ExtensionPresenceCriticalDescription
authorityKeyIdentifierMUSTNSee Section 7.1.2.11.1
basicConstraintsMUSTYSee Section 7.1.2.10.4
crlDistributionPointsMUSTNSee Section 7.1.2.11.2
keyUsageMUSTYSee Section 7.1.2.10.7
subjectKeyIdentifierMUSTNSee Section 7.1.2.11.4
extKeyUsageMUST1NSee Section 7.1.2.3.3
authorityInformationAccessSHOULDNSee Section 7.1.2.10.3
certificatePoliciesMAYNSee Section 7.1.2.3.2
nameConstraintsMAY*2See Section 7.1.2.10.8
Signed Certificate Timestamp ListMAYNSee Section 7.1.2.11.3
Any other extensionNOT RECOMMENDED-See Section 7.1.2.11.5
擴充欄位必要性關鍵性說明
authorityKeyIdentifier應(MUST)N參見第 7.1.2.11.1 節
basicConstraints應(MUST)Y參見第 7.1.2.10.4 節
crlDistributionPoints應(MUST)N參見第 7.1.2.11.2 節
keyUsage應(MUST)Y參見第 7.1.2.10.7 節
subjectKeyIdentifier應(MUST)N參見第 7.1.2.11.4 節
extKeyUsage應(MUST)1N參見第 7.1.2.3.3 節
authorityInformationAccess宜(SHOULD)N參見第 7.1.2.10.3 節
certificatePolicies得(MAY)N參見第 7.1.2.3.2 節
nameConstraints得(MAY)*2參見第 7.1.2.10.8 節
Signed Certificate Timestamp(SCT)清單得(MAY)N參見第 7.1.2.11.3 節
任何其他擴充欄位不建議(NOT RECOMMENDED)-參見第 7.1.2.11.5 節

註腳

  1. While RFC 5280, Section 4.2.1.12 notes that this extension will generally only appear within end-entity certificates, these Requirements make use of this extension to further protect relying parties by limiting the scope of CA Certificates, as implemented by a number of Application Software Suppliers. ↩

  2. See Section 7.1.2.10.8 for further requirements, including regarding criticality of this extension. ↩

  3. 雖然 RFC 5280 第 4.2.1.12 節 指出,此擴充欄位通常僅出現於終端個體憑證,但本文件利用此擴充欄位以限制 CA 憑證(根憑證除外)的適用範圍;藉由此種限制,可進一步保護信賴憑證者(Relying Party),且此做法已由多家應用軟體供應商實作。 ↩

  4. 有關此擴充欄位之進一步要求,包括是否標記為關鍵(critical)的相關要求,參見第 7.1.2.10.8 節。 ↩