7.1.2.6.1 已翻譯 對應原文版本:2.3.0

TLS 下屬憑證機構(TLS Subordinate CA Extensions)之擴充欄位

跳至原文

TLS Subordinate CA Extensions

ExtensionPresenceCriticalDescription
authorityKeyIdentifierMUSTNSee Section 7.1.2.11.1
basicConstraintsMUSTYSee Section 7.1.2.10.4
certificatePoliciesMUSTNSee Section 7.1.2.10.5
crlDistributionPointsMUSTNSee Section 7.1.2.11.2
keyUsageMUSTYSee Section 7.1.2.10.7
subjectKeyIdentifierMUSTNSee Section 7.1.2.11.4
extKeyUsageMUST1NSee Section 7.1.2.10.6
authorityInformationAccessSHOULDNSee Section 7.1.2.10.3
nameConstraintsMAY*2See Section 7.1.2.10.8
Signed Certificate Timestamp ListMAYNSee Section 7.1.2.11.3
Any other extensionNOT RECOMMENDED-See Section 7.1.2.11.5
擴充欄位必要性關鍵性說明
authorityKeyIdentifier應(MUST)N參見第 7.1.2.11.1 節
basicConstraints應(MUST)Y參見第 7.1.2.10.4 節
certificatePolicies應(MUST)N參見第 7.1.2.10.5 節
crlDistributionPoints應(MUST)N參見第 7.1.2.11.2 節
keyUsage應(MUST)Y參見第 7.1.2.10.7 節
subjectKeyIdentifier應(MUST)N參見第 7.1.2.11.4 節
extKeyUsage應(MUST)1N參見第 7.1.2.10.6 節
authorityInformationAccess宜(SHOULD)N參見第 7.1.2.10.3 節
nameConstraints得(MAY)*2參見第 7.1.2.10.8 節
Signed Certificate Timestamp(SCT)清單得(MAY)N參見第 7.1.2.11.3 節
任何其他擴充欄位不建議(NOT RECOMMENDED)-參見第 7.1.2.11.5 節

註腳

  1. While RFC 5280, Section 4.2.1.12 notes that this extension will generally only appear within end-entity certificates, these Requirements make use of this extension to further protect relying parties by limiting the scope of CA Certificates, as implemented by a number of Application Software Suppliers. ↩

  2. See Section 7.1.2.10.8 for further requirements, including regarding criticality of this extension. ↩

  3. 雖然 RFC 5280 第 4.2.1.12 節 指出,此擴充欄位通常僅出現於終端個體憑證,但本文件利用此擴充欄位以限制 CA 憑證(根憑證除外)的適用範圍;藉由此種限制,可進一步保護信賴憑證者(Relying Party),且此做法已由多家應用軟體供應商實作。 ↩

  4. 有關此擴充欄位之進一步要求,包括是否標記為關鍵(critical)的相關要求,參見第 7.1.2.10.8 節。 ↩