用戶憑證(Subscriber Certificate)之主體別名(Subject Alternative Name)
Subscriber Certificate Subject Alternative Name
For Subscriber Certificates, the Subject Alternative Name MUST be present and MUST contain at least one
dNSNameoriPAddressGeneralName. See below for further requirements about the permitted fields and their validation requirements.
用戶憑證之主體別名(Subject Alternative Name)應(MUST)存在,且應(MUST)包含至少一個 dNSName 或 iPAddress GeneralName。有關可否設定之欄位及其驗證要求,詳見下文。
If the
subjectfield of the certificate is an empty SEQUENCE, this extension MUST be marked critical, as specified in RFC 5280, Section 4.2.1.6. Otherwise, this extension MUST NOT be marked critical.
若憑證之 subject 欄位為空序列(empty SEQUENCE),本擴充欄位應(MUST)標記為關鍵(critical),如 RFC 5280 第 4.2.1.6 節 所規定。否則,本擴充欄位不得(MUST NOT)標記為關鍵(critical)。
GeneralNamewithin asubjectAltNameextensionName Type Permitted Validation otherNameN - rfc822NameN - dNSNameY The entry MUST contain either a Fully-Qualified Domain Name or Wildcard Domain Name that the CA has validated in accordance with Section 3.2.2.4. Wildcard Domain Names MUST be validated for consistency with Section 3.2.2.6. The entry MUST NOT contain an Internal Name. Effective 2026-03-15, the entry MUST NOT contain a Domain Name that ends in an IP Address Reverse Zone Suffix. The Fully-Qualified Domain Name or the FQDN portion of the Wildcard Domain Name contained in the entry MUST be composed entirely of P-Labels or Non-Reserved LDH Labels joined together by a U+002E FULL STOP (”.”) character. The zero-length Domain Label representing the root zone of the Internet Domain Name System MUST NOT be included (e.g. “example.com” MUST be encoded as “example.com” and MUST NOT be encoded as “example.com.”). x400AddressN - directoryNameN - ediPartyNameN - uniformResourceIdentifierN - iPAddressY The entry MUST contain the IPv4 or IPv6 address that the CA has confirmed the Applicant controls or has been granted the right to use through a method specified in Section 3.2.2.5. The entry MUST NOT contain a Reserved IP Address. registeredIDN -
GeneralName 名稱類型 | 可否設定 | 驗證方法 |
|---|---|---|
otherName | N | - |
rfc822Name | N | - |
dNSName | Y | 該項目應(MUST)包含 CA 已依第 3.2.2.4 節驗證之完全吻合網域名稱(FQDN)或萬用網域名稱(Wildcard Domain Name)。萬用網域名稱應(MUST)依第 3.2.2.6 節進行驗證,以確認符合該節之規定。該項目不得(MUST NOT)包含內部名稱(Internal Name)。自 2026-03-15 起,該項目不得(MUST NOT)包含以 IP 位址反向區域後綴(IP Address Reverse Zone Suffix)結尾之網域名稱。該項目所含之完全吻合網域名稱(FQDN),或萬用網域名稱之 FQDN 部分,應(MUST)完全由 P-Labels 或非保留 LDH 標籤(Non-Reserved LDH Labels)組成,並以 U+002E FULL STOP(「.」)字元相互連接。代表網際網路網域名稱系統(DNS)根區域(root zone)之零長度網域標籤(zero-length Domain Label)不得(MUST NOT)包含於其中(例如,「example.com」應(MUST)編碼為「example.com」,而不得(MUST NOT)編碼為「example.com.」)。 |
x400Address | N | - |
directoryName | N | - |
ediPartyName | N | - |
uniformResourceIdentifier | N | - |
iPAddress | Y | 該項目應(MUST)包含 CA 已透過第 3.2.2.5 節所規定之方法,確認申請者控管權或已獲授權使用 IPv4 或 IPv6 位址。該項目不得(MUST NOT)包含保留 IP 位址(Reserved IP Address)。 |
registeredID | N | - |
Note: As an explicit exception from RFC 5280, P-Labels are permitted to not conform to IDNA 2003. These Requirements allow for the inclusion of P-Labels that do not conform with IDNA 2003 to support newer versions of the Unicode character repertoire, among other improvements to the various IDNA standards.
注意:作為 RFC 5280 之明確例外,P-Labels 可不符合 IDNA 2003。本文件允許包含不符合 IDNA 2003 之 P-Labels,以支援各項 IDNA 標準之改進,包括支援較新版本之 Unicode 字元範圍(character repertoire)。