7.1.2.5.2 已翻譯 對應原文版本:2.3.0

受技術約束之 TLS 下屬憑證機構(Technically Constrained Non-TLS Subordinate CA)之名稱限制(Name Constraints)

跳至原文

Technically Constrained TLS Subordinate CA Name Constraints

For a TLS Subordinate CA to be Technically Constrained, Name Constraints extension MUST be encoded as follows. As an explicit exception from RFC 5280, this extension SHOULD be marked critical, but MAY be marked non-critical if compatibility with certain legacy applications that do not support Name Constraints is necessary.

TLS 下屬憑證機構(Subordinate CA)若欲成為受技術約束(Technically Constrained),名稱限制(Name Constraints)擴充欄位應(MUST)依以下方式編碼。作為 RFC 5280 之明確例外,本擴充欄位宜(SHOULD)標記為關鍵(critical),但若需與某些不支援名稱限制之舊版應用程式相容,得(MAY)標記為非關鍵(non-critical)。

nameConstraints requirements
FieldDescription
permittedSubtreesThe permittedSubtrees MUST contain at least one GeneralSubtree for both of the dNSName and iPAddress GeneralName name types, UNLESS the specified GeneralName name type appears within the excludedSubtrees to exclude all names of that name type. Additionally, the permittedSubtrees MUST contain at least one GeneralSubtree of the directoryName GeneralName name type.
GeneralSubtreeThe requirements for a GeneralSubtree that appears within a permittedSubtrees.
baseSee following table.
minimumMUST NOT be present.
maximumMUST NOT be present.
excludedSubtreesThe excludedSubtrees MUST contain at least one GeneralSubtree for each of the dNSName and iPAddress GeneralName name types, unless there is an instance present of that name type in the permittedSubtrees. The directoryName name type is NOT RECOMMENDED.
GeneralSubtreeThe requirements for a GeneralSubtree that appears within a permittedSubtrees.
baseSee following table.
minimumMUST NOT be present.
maximumMUST NOT be present.
nameConstraints 要求規定
欄位說明
permittedSubtreespermittedSubtrees 應(MUST)對每一種 dNSName 與 iPAddress GeneralName 名稱類型,各包含至少一個 GeneralSubtree,除非該 GeneralName 名稱類型已出現於 excludedSubtrees 中,用以排除該名稱類型之所有值。此外,permittedSubtrees 應(MUST)包含至少一個 directoryName GeneralName 名稱類型的 GeneralSubtree。
GeneralSubtree符合 permittedSubtrees 中各 GeneralSubtree 之要求規定。
base參見下表
minimum不得(MUST NOT)存在
maximum不得(MUST NOT)存在
excludedSubtreesexcludedSubtrees 應(MUST)對每一種 dNSName 與 iPAddress GeneralName 名稱類型,各包含至少一個 GeneralSubtree,除非 permittedSubtrees 中已包含該名稱類型的 GeneralSubtree。不建議(NOT RECOMMENDED)使用 directoryName 名稱類型。
GeneralSubtree符合 permittedSubtrees 中各 GeneralSubtree 之要求規定。
base參見下表
minimum不得(MUST NOT)存在
maximum不得(MUST NOT)存在

The following table contains the requirements for the GeneralName that appears within the base of a GeneralSubtree in either the permittedSubtrees or excludedSubtrees.

下表列出 permittedSubtrees 或 excludedSubtrees 中各 GeneralSubtree 之 base 所包含的 GeneralName 要求規定。

GeneralName requirements for the base field
Name TypePresencePermitted SubtreesExcluded SubtreesEntire Namespace Exclusion
dNSNameMUSTThe CA MUST confirm that the Applicant has registered the dNSName or has been authorized by the domain registrant to act on the registrant’s behalf. See Section 3.2.2.4.If at least one dNSName instance is present in the permittedSubtrees, the CA MAY indicate one or more subordinate domains to be excluded.If no dNSName instance is present in the permittedSubtrees, then the CA MUST include a zero-length dNSName to indicate no domain names are permitted.
iPAddressMUSTThe CA MUST confirm that the Applicant has been assigned the iPAddress range or has been authorized by the assigner to act on the assignee’s behalf. See Section 3.2.2.5.If at least one iPAddress instance is present in the permittedSubtrees, the CA MAY indicate one or more subdivisions of those ranges to be excluded.If no IPv4 iPAddress is present in the permittedSubtrees, the CA MUST include an iPAddress of 8 zero octets, indicating the IPv4 range of 0.0.0.0/0 being excluded. If no IPv6 iPAddress is present in the permittedSubtrees, the CA MUST include an iPAddress of 32 zero octets, indicating the IPv6 range of ::0/0 being excluded.
directoryNameMUSTThe CA MUST confirm the Applicant’s and/or Subsidiary’s name attributes such that all certificates issued will comply with the relevant Certificate Profile (see Section 7.1.2), including Name Forms (See Section 7.1.4).It is NOT RECOMMENDED to include values within excludedSubtrees.The CA MUST include a value within permittedSubtrees, and as such, this does not apply. See the Excluded Subtrees requirements for more.
otherNameNOT RECOMMENDEDSee belowSee belowSee below
Any other valueMUST NOT---
base 欄位所包含之 GeneralName 要求規定
GeneralName 名稱類型必要性permittedSubtreesexcludedSubtrees排除該類型整個 Namespace
dNSName應(MUST)CA 應(MUST)確認申請者已註冊該 dNSName,或已獲網域名稱註冊人授權代表該註冊人行事。參見第 3.2.2.4 節。若 permittedSubtrees 中至少存在一個 dNSName,CA 得(MAY)於 excludedSubtrees 指定 dNSName 網域之一個或多個子網域名稱作為欲排除項目。若 permittedSubtrees 中不存在任何 dNSName,CA 應(MUST)於 permittedSubtrees 包含一個零長度(空字串)的 dNSName,以表示不允許任何網域名稱。
iPAddress應(MUST)CA 應(MUST)確認申請者已被指配該 iPAddress 範圍,或已獲 IP 位址分配者(assigner)授權代表被指配者(assignee)行事。參見第 3.2.2.5 節。若 permittedSubtrees 中至少存在一個 iPAddress,CA 得(MAY)於 excludedSubtrees 指定該等 iPAddress 範圍內之一個或多個子網段作為欲排除項目。若 permittedSubtrees 中未包含任何 IPv4 iPAddress,CA 應(MUST)於 permittedSubtrees 包含一個由 8 個零位元組組成的 iPAddress,表示排除整個 IPv4 位址範圍(0.0.0.0/0)。若 permittedSubtrees 中未包含任何 IPv6 iPAddress,CA 應(MUST)於 permittedSubtrees 包含一個由 32 個零位元組組成的 iPAddress,表示排除整個 IPv6 位址範圍(::0/0)。
directoryName應(MUST)CA 應(MUST)確認申請者及/或其子公司之名稱屬性,以確保所有簽發之憑證均遵循相關憑證剖繪(參見第 7.1.2 節),包含名稱形式(參見第 7.1.4 節)。不建議(NOT RECOMMENDED)於 excludedSubtrees 中包含任何值。CA 應(MUST)於 permittedSubtrees 中包含一個值,因此本欄位不適用。詳見 excludedSubtrees 之相關規定。
otherName不建議(NOT RECOMMENDED)參見下文參見下文參見下文
任何其他值不得(MUST NOT)---

Any otherName, if present:

任何 otherName,若存在:

  1. MUST apply in the context of the public Internet, unless:
    1. the type-id falls within an OID arc for which the Applicant demonstrates ownership, or,
    2. the Applicant can otherwise demonstrate the right to assert the data in a public context.
  2. MUST NOT include semantics that will mislead the Relying Party about certificate information verified by the CA.
  3. MUST be DER encoded according to the relevant ASN.1 module defining the otherName type-id and value.
  1. 應(MUST)適用於公共網際網路,除非:
    1. type-id 位於申請者能證明擁有其所有權之 OID arc 範圍內,或
    2. 申請者能以其他方式證明其有權於公共網際網路中聲明該資料。
  2. 不得(MUST NOT)具有可能使信賴憑證者對 CA 所驗證之憑證資訊產生誤解的含義。
  3. 應(MUST)依相關 ASN.1 模組中對該 otherName 的 type-id 與 value 之定義,以 DER 進行編碼。

CAs SHALL NOT include additional names unless the CA is aware of a reason for including the data in the Certificate.

CA 不得(SHALL NOT)包含額外名稱(例如額外的 GeneralName),除非 CA 知悉有正當理由於憑證中包含該資料。