受技術約束之 TLS 下屬憑證機構(Technically Constrained Non-TLS Subordinate CA)之名稱限制(Name Constraints)
Technically Constrained TLS Subordinate CA Name Constraints
For a TLS Subordinate CA to be Technically Constrained, Name Constraints extension MUST be encoded as follows. As an explicit exception from RFC 5280, this extension SHOULD be marked critical, but MAY be marked non-critical if compatibility with certain legacy applications that do not support Name Constraints is necessary.
TLS 下屬憑證機構(Subordinate CA)若欲成為受技術約束(Technically Constrained),名稱限制(Name Constraints)擴充欄位應(MUST)依以下方式編碼。作為 RFC 5280 之明確例外,本擴充欄位宜(SHOULD)標記為關鍵(critical),但若需與某些不支援名稱限制之舊版應用程式相容,得(MAY)標記為非關鍵(non-critical)。
nameConstraintsrequirementsField Description permittedSubtreesThe permittedSubtreesMUST contain at least oneGeneralSubtreefor both of thedNSNameandiPAddressGeneralNamename types, UNLESS the specifiedGeneralNamename type appears within theexcludedSubtreesto exclude all names of that name type. Additionally, thepermittedSubtreesMUST contain at least oneGeneralSubtreeof thedirectoryNameGeneralNamename type.GeneralSubtreeThe requirements for a GeneralSubtreethat appears within apermittedSubtrees.baseSee following table. minimumMUST NOT be present. maximumMUST NOT be present. excludedSubtreesThe excludedSubtreesMUST contain at least oneGeneralSubtreefor each of thedNSNameandiPAddressGeneralNamename types, unless there is an instance present of that name type in thepermittedSubtrees. ThedirectoryNamename type is NOT RECOMMENDED.GeneralSubtreeThe requirements for a GeneralSubtreethat appears within apermittedSubtrees.baseSee following table. minimumMUST NOT be present. maximumMUST NOT be present.
| 欄位 | 說明 |
|---|---|
permittedSubtrees | permittedSubtrees 應(MUST)對每一種 dNSName 與 iPAddress GeneralName 名稱類型,各包含至少一個 GeneralSubtree,除非該 GeneralName 名稱類型已出現於 excludedSubtrees 中,用以排除該名稱類型之所有值。此外,permittedSubtrees 應(MUST)包含至少一個 directoryName GeneralName 名稱類型的 GeneralSubtree。 |
GeneralSubtree | 符合 permittedSubtrees 中各 GeneralSubtree 之要求規定。 |
base | 參見下表 |
minimum | 不得(MUST NOT)存在 |
maximum | 不得(MUST NOT)存在 |
excludedSubtrees | excludedSubtrees 應(MUST)對每一種 dNSName 與 iPAddress GeneralName 名稱類型,各包含至少一個 GeneralSubtree,除非 permittedSubtrees 中已包含該名稱類型的 GeneralSubtree。不建議(NOT RECOMMENDED)使用 directoryName 名稱類型。 |
GeneralSubtree | 符合 permittedSubtrees 中各 GeneralSubtree 之要求規定。 |
base | 參見下表 |
minimum | 不得(MUST NOT)存在 |
maximum | 不得(MUST NOT)存在 |
The following table contains the requirements for the
GeneralNamethat appears within thebaseof aGeneralSubtreein either thepermittedSubtreesorexcludedSubtrees.
下表列出 permittedSubtrees 或 excludedSubtrees 中各 GeneralSubtree 之 base 所包含的 GeneralName 要求規定。
GeneralNamerequirements for thebasefieldName Type Presence Permitted Subtrees Excluded Subtrees Entire Namespace Exclusion dNSNameMUST The CA MUST confirm that the Applicant has registered the dNSNameor has been authorized by the domain registrant to act on the registrant’s behalf. See Section 3.2.2.4.If at least one dNSNameinstance is present in thepermittedSubtrees, the CA MAY indicate one or more subordinate domains to be excluded.If no dNSNameinstance is present in thepermittedSubtrees, then the CA MUST include a zero-lengthdNSNameto indicate no domain names are permitted.iPAddressMUST The CA MUST confirm that the Applicant has been assigned the iPAddressrange or has been authorized by the assigner to act on the assignee’s behalf. See Section 3.2.2.5.If at least one iPAddressinstance is present in thepermittedSubtrees, the CA MAY indicate one or more subdivisions of those ranges to be excluded.If no IPv4 iPAddressis present in thepermittedSubtrees, the CA MUST include aniPAddressof 8 zero octets, indicating the IPv4 range of 0.0.0.0/0 being excluded. If no IPv6iPAddressis present in thepermittedSubtrees, the CA MUST include aniPAddressof 32 zero octets, indicating the IPv6 range of ::0/0 being excluded.directoryNameMUST The CA MUST confirm the Applicant’s and/or Subsidiary’s name attributes such that all certificates issued will comply with the relevant Certificate Profile (see Section 7.1.2), including Name Forms (See Section 7.1.4). It is NOT RECOMMENDED to include values within excludedSubtrees.The CA MUST include a value within permittedSubtrees, and as such, this does not apply. See the Excluded Subtrees requirements for more.otherNameNOT RECOMMENDED See below See below See below Any other value MUST NOT - - -
GeneralName 名稱類型 | 必要性 | permittedSubtrees | excludedSubtrees | 排除該類型整個 Namespace |
|---|---|---|---|---|
dNSName | 應(MUST) | CA 應(MUST)確認申請者已註冊該 dNSName,或已獲網域名稱註冊人授權代表該註冊人行事。參見第 3.2.2.4 節。 | 若 permittedSubtrees 中至少存在一個 dNSName,CA 得(MAY)於 excludedSubtrees 指定 dNSName 網域之一個或多個子網域名稱作為欲排除項目。 | 若 permittedSubtrees 中不存在任何 dNSName,CA 應(MUST)於 permittedSubtrees 包含一個零長度(空字串)的 dNSName,以表示不允許任何網域名稱。 |
iPAddress | 應(MUST) | CA 應(MUST)確認申請者已被指配該 iPAddress 範圍,或已獲 IP 位址分配者(assigner)授權代表被指配者(assignee)行事。參見第 3.2.2.5 節。 | 若 permittedSubtrees 中至少存在一個 iPAddress,CA 得(MAY)於 excludedSubtrees 指定該等 iPAddress 範圍內之一個或多個子網段作為欲排除項目。 | 若 permittedSubtrees 中未包含任何 IPv4 iPAddress,CA 應(MUST)於 permittedSubtrees 包含一個由 8 個零位元組組成的 iPAddress,表示排除整個 IPv4 位址範圍(0.0.0.0/0)。若 permittedSubtrees 中未包含任何 IPv6 iPAddress,CA 應(MUST)於 permittedSubtrees 包含一個由 32 個零位元組組成的 iPAddress,表示排除整個 IPv6 位址範圍(::0/0)。 |
directoryName | 應(MUST) | CA 應(MUST)確認申請者及/或其子公司之名稱屬性,以確保所有簽發之憑證均遵循相關憑證剖繪(參見第 7.1.2 節),包含名稱形式(參見第 7.1.4 節)。 | 不建議(NOT RECOMMENDED)於 excludedSubtrees 中包含任何值。 | CA 應(MUST)於 permittedSubtrees 中包含一個值,因此本欄位不適用。詳見 excludedSubtrees 之相關規定。 |
otherName | 不建議(NOT RECOMMENDED) | 參見下文 | 參見下文 | 參見下文 |
| 任何其他值 | 不得(MUST NOT) | - | - | - |
Any
otherName, if present:
任何 otherName,若存在:
- MUST apply in the context of the public Internet, unless:
- the
type-idfalls within an OID arc for which the Applicant demonstrates ownership, or,- the Applicant can otherwise demonstrate the right to assert the data in a public context.
- MUST NOT include semantics that will mislead the Relying Party about certificate information verified by the CA.
- MUST be DER encoded according to the relevant ASN.1 module defining the
otherNametype-idandvalue.
- 應(MUST)適用於公共網際網路,除非:
type-id位於申請者能證明擁有其所有權之 OID arc 範圍內,或- 申請者能以其他方式證明其有權於公共網際網路中聲明該資料。
- 不得(MUST NOT)具有可能使信賴憑證者對 CA 所驗證之憑證資訊產生誤解的含義。
- 應(MUST)依相關 ASN.1 模組中對該
otherName的type-id與value之定義,以 DER 進行編碼。
CAs SHALL NOT include additional names unless the CA is aware of a reason for including the data in the Certificate.
CA 不得(SHALL NOT)包含額外名稱(例如額外的 GeneralName),除非 CA 知悉有正當理由於憑證中包含該資料。