受技術約束之預簽憑證簽章憑證機構(Technically Constrained Precertificate Signing CA)憑證剖繪
Technically Constrained Precertificate Signing CA Certificate Profile
This Certificate Profile MUST be used when issuing a CA Certificate that will be used as a Precertificate Signing CA, as described in RFC 6962, Section 3.1. If a CA Certificate conforms to this profile, it is considered Technically Constrained.
當簽發一張將用作 RFC 6962 第 3.1 節 所述之預簽憑證簽章憑證機構(Precertificate Signing CA)之 CA 憑證時,應(MUST)使用本憑證剖繪。若該 CA 憑證符合本剖繪,則視為受技術約束(Technically Constrained)。
A Precertificate Signing CA MUST only be used to sign Precertificates, as defined in Section 7.1.2.9. When a Precertificate Signing CA issues a Precertificate, it shall be interpreted as if the Issuing CA of the Precertificate Signing CA has issued a Certificate with a matching
tbsCertificateof the Precertificate, after applying the modifications specified in RFC 6962, Section 3.2.
預簽憑證簽章憑證機構(Precertificate Signing CA)應(MUST)僅用於簽章第 7.1.2.9 節所定義之預簽憑證。當預簽憑證簽章憑證機構簽發預簽憑證時,應將其解釋為:在規範上視同該預簽憑證簽章憑證機構(Precertificate Signing CA)的簽發憑證機構(Issuing CA),已簽發一張有效憑證;該有效憑證之 tbsCertificate 與依照 RFC 6962 第 3.2 節 規定之修改套用後的相對應預簽憑證之 tbsCertificate 相符。
As noted in RFC 6962, Section 3.2, the
signaturefield of a Precertificate is not altered as part of these modifications. As such, the Precertificate Signing CA MUST use the same signature algorithm as the Issuing CA when issuing Precertificates, and, correspondingly, MUST use a public key of the same public key algorithm as the Issuing CA, although MAY use a different CA Key Pair.
如 RFC 6962 第 3.2 節 所述,預簽憑證的 signature 欄位不會因上述修改而改變。因此,預簽憑證簽章憑證機構(Precertificate Signing CA)在簽發預簽憑證時,應(MUST)使用與簽發憑證機構(Issuing CA)相同之簽章演算法;同樣地,其公開金鑰應(MUST)使用與簽發憑證機構(Issuing CA)相同之公開金鑰演算法,但得(MAY)使用不同之 CA 金鑰對。
Field Description tbsCertificateversionMUST be v3(2) serialNumberMUST be a non-sequential number greater than zero (0) and less than 2¹⁵⁹ containing at least 64 bits of output from a CSPRNG. signatureSee Section 7.1.3.2 issuerMUST be byte-for-byte identical to the subjectfield of the Issuing CA. See Section 7.1.4.1validitySee Section 7.1.2.10.1 subjectSee Section 7.1.2.10.2 subjectPublicKeyInfoThe algorithm identifier MUST be byte-for-byte identical to the algorithm identifier of the subjectPublicKeyInfofield of the Issuing CA. See Section 7.1.3.1issuerUniqueIDMUST NOT be present subjectUniqueIDMUST NOT be present extensionsSee Section 7.1.2.4.1 signatureAlgorithmEncoded value MUST be byte-for-byte identical to the tbsCertificate.signature.signature
| 欄位 | 說明 |
|---|---|
tbsCertificate | |
version | 應(MUST)為 v3(2) |
serialNumber | 應(MUST)為一個非連續之數值,其值大於 0 且小於 2¹⁵⁹,且其中至少 64 個位元應來自 CSPRNG 之輸出。 |
signature | 參見第 7.1.3.2 節 |
issuer | 應(MUST)與簽發憑證機構(Issuing CA)之 subject 欄位逐位元組完全相同。參見第 7.1.4.1 節 |
validity | 參見第 7.1.2.10.1 節 |
subject | 參見第 7.1.2.10.2 節 |
subjectPublicKeyInfo | 演算法識別碼(algorithm identifier)應(MUST)與簽發憑證機構(Issuing CA)的 subjectPublicKeyInfo 欄位中之演算法識別碼逐位元組完全相同。參見第 7.1.3.1 節 |
issuerUniqueID | 不得(MUST NOT)存在 |
subjectUniqueID | 不得(MUST NOT)存在 |
extensions | 參見第 7.1.2.4.1 節 |
signatureAlgorithm | 編碼後之值應(MUST)與 tbsCertificate.signature 逐位元組完全相同 |
signature |
Effective 2026-03-15:
- This Certificate Profile MUST NOT be used.
- Precertificate Signing CAs MUST NOT be used to issue Precertificates.
自 2026-03-15 起:
- 本憑證剖繪不得(MUST NOT)使用。
- 預簽憑證簽章憑證機構(Precertificate Signing CA)不得(MUST NOT)用於簽發預簽憑證。