7.1.2.3.3 已翻譯 對應原文版本:2.3.0
受技術約束之非 TLS 下屬憑證機構(Technically Constrained Non-TLS Subordinate CA)之擴充金鑰使用方法(Extended Key Usage)
Technically Constrained Non-TLS Subordinate CA Extended Key Usage
The Issuing CA MUST verify that the Subordinate CA Certificate is authorized to issue certificates for each included extended key usage purpose. Multiple, independent key purposes (e.g.
id-kp-timeStampingandid-kp-codeSigning) are NOT RECOMMENDED.
簽發憑證機構(Issuing CA)應(MUST)驗證下屬憑證機構憑證(Subordinate CA Certificate)是否經授權得針對該憑證所含之每項擴充金鑰使用方法之適用目的簽發憑證。不建議(NOT RECOMMENDED)包含多個彼此獨立的金鑰使用方法之適用目的(例如同時包含 id-kp-timeStamping 與 id-kp-codeSigning)。
Key Purpose OID Presence id-kp-serverAuth1.3.6.1.5.5.7.3.1 MUST NOT id-kp-OCSPSigning1.3.6.1.5.5.7.3.9 MUST NOT anyExtendedKeyUsage2.5.29.37.0 MUST NOT Precertificate Signing Certificate 1.3.6.1.4.1.11129.2.4.4 MUST NOT Any other value - MAY
| 金鑰適用目的(Key Purpose) | OID | 必要性 |
|---|---|---|
id-kp-serverAuth | 1.3.6.1.5.5.7.3.1 | 不得(MUST NOT) |
id-kp-OCSPSigning | 1.3.6.1.5.5.7.3.9 | 不得(MUST NOT) |
anyExtendedKeyUsage | 2.5.29.37.0 | 不得(MUST NOT) |
| 預簽憑證簽章憑證 | 1.3.6.1.4.1.11129.2.4.4 | 不得(MUST NOT) |
| 任何其他值 | - | 得(MAY) |