7.1.2.3.1 已翻譯 對應原文版本:2.3.0
受技術約束之非 TLS 下屬憑證機構(Technically Constrained Non-TLS Subordinate CA)之擴充欄位
Technically Constrained Non-TLS Subordinate CA Extensions
Extension Presence Critical Description authorityKeyIdentifierMUST N See Section 7.1.2.11.1 basicConstraintsMUST Y See Section 7.1.2.10.4 crlDistributionPointsMUST N See Section 7.1.2.11.2 keyUsageMUST Y See Section 7.1.2.10.7 subjectKeyIdentifierMUST N See Section 7.1.2.11.4 extKeyUsageMUST1 N See Section 7.1.2.3.3 authorityInformationAccessSHOULD N See Section 7.1.2.10.3 certificatePoliciesMAY N See Section 7.1.2.3.2 nameConstraintsMAY *2 See Section 7.1.2.10.8 Signed Certificate Timestamp List MAY N See Section 7.1.2.11.3 Any other extension NOT RECOMMENDED - See Section 7.1.2.11.5
| 擴充欄位 | 必要性 | 關鍵性 | 說明 |
|---|---|---|---|
authorityKeyIdentifier | 應(MUST) | N | 參見第 7.1.2.11.1 節 |
basicConstraints | 應(MUST) | Y | 參見第 7.1.2.10.4 節 |
crlDistributionPoints | 應(MUST) | N | 參見第 7.1.2.11.2 節 |
keyUsage | 應(MUST) | Y | 參見第 7.1.2.10.7 節 |
subjectKeyIdentifier | 應(MUST) | N | 參見第 7.1.2.11.4 節 |
extKeyUsage | 應(MUST)1 | N | 參見第 7.1.2.3.3 節 |
authorityInformationAccess | 宜(SHOULD) | N | 參見第 7.1.2.10.3 節 |
certificatePolicies | 得(MAY) | N | 參見第 7.1.2.3.2 節 |
nameConstraints | 得(MAY) | *2 | 參見第 7.1.2.10.8 節 |
| Signed Certificate Timestamp(SCT)清單 | 得(MAY) | N | 參見第 7.1.2.11.3 節 |
| 任何其他擴充欄位 | 不建議(NOT RECOMMENDED) | - | 參見第 7.1.2.11.5 節 |
註腳
-
While RFC 5280, Section 4.2.1.12 notes that this extension will generally only appear within end-entity certificates, these Requirements make use of this extension to further protect relying parties by limiting the scope of CA Certificates, as implemented by a number of Application Software Suppliers. ↩
-
See Section 7.1.2.10.8 for further requirements, including regarding criticality of this extension. ↩
-
雖然 RFC 5280 第 4.2.1.12 節 指出,此擴充欄位通常僅出現於終端個體憑證,但本文件利用此擴充欄位以限制 CA 憑證(根憑證除外)的適用範圍;藉由此種限制,可進一步保護信賴憑證者(Relying Party),且此做法已由多家應用軟體供應商實作。 ↩
-
有關此擴充欄位之進一步要求,包括是否標記為關鍵(critical)的相關要求,參見第 7.1.2.10.8 節。 ↩