個人驗證型(IV)用戶憑證剖繪
Individual Validated
For a Subscriber Certificate to be Individual Validated, it MUST meet the following profile:
若用戶憑證屬於個人驗證型(Individual Validated)憑證,應(MUST)符合下列剖繪:
Field Requirements subjectSee following table. certificatePoliciesMUST be present. MUST assert the Reserved Certificate Policy Identifier of 2.23.140.1.2.3as apolicyIdentifier. See Section 7.1.2.7.9.All other extensions See Section 7.1.2.7.6
| 欄位 | 要求 |
|---|---|
subject | 參見下表 |
certificatePolicies | 應(MUST)存在。應(MUST)使用 policyIdentifier 宣告保留憑證政策識別碼 2.23.140.1.2.3。參見第 7.1.2.7.9 節。 |
| 所有其他擴充欄位 | 參見第 7.1.2.7.6 節 |
All
subjectnames MUST be encoded as specified in Section 7.1.4.
所有 subject 名稱應(MUST)依第 7.1.4 節規定之方式編碼。
The following table details the acceptable
AttributeTypes that may appear within thetypefield of anAttributeTypeAndValue, as well as the contents permitted within thevaluefield.
下表列出 AttributeTypeAndValue 之 type 欄位允許使用的 AttributeType,以及對應之 value 欄位允許填列的內容。
Individual Validated subjectAttributesAttribute Name Presence Value Verification countryNameMUST The two-letter ISO 3166-1 country code for the country associated with the Subject. If a Country is not represented by an official ISO 3166-1 country code, the CA MUST specify the ISO 3166-1 user-assigned code of XX, indicating that an official ISO 3166-1 alpha-2 code has not been assigned.Section 3.2.3 stateOrProvinceNameMUST / MAY MUST be present if localityNameis absent, MAY be present otherwise. If present, MUST contain the Subject’s state or province information.Section 3.2.3 localityNameMUST / MAY MUST be present if stateOrProvinceNameis absent, MAY be present otherwise. If present, MUST contain the Subject’s locality information.Section 3.2.3 postalCodeNOT RECOMMENDED If present, MUST contain the Subject’s zip or postal information. Section 3.2.3 streetAddressNOT RECOMMENDED If present, MUST contain the Subject’s street address information. Multiple instances MAY be present. Section 3.2.3 organizationNameNOT RECOMMENDED If present, MUST contain the Subject’s name and/or DBA/tradename. The CA MAY include information in this field that differs slightly from the verified name, such as common variations or abbreviations, provided that the CA documents the difference and any abbreviations used are locally accepted abbreviations. If both are included, the DBA/tradename SHALL appear first, followed by the Subject’s name in parentheses. Section 3.2.3 surnameMUST The Subject’s surname. Section 3.2.3 givenNameMUST The Subject’s given name. Section 3.2.3 organizationalUnitNameMUST NOT - - commonNameNOT RECOMMENDED If present, MUST contain a value derived from the subjectAltNameextension according to Section 7.1.4.3.Any other attribute NOT RECOMMENDED - See Section 7.1.4.4
AttributeType 屬性名稱 | 必要性 | value | 驗證方法 |
|---|---|---|---|
countryName | 應(MUST) | 與主體關聯之國家的兩字母 ISO 3166-1 國家代碼。若該國家未獲正式 ISO 3166-1 國家代碼,CA 應(MUST)指定 ISO 3166-1 使用者保留代碼 XX,以表示尚未被分配正式 ISO 3166-1 雙字母代碼。 | 第 3.2.3 節 |
stateOrProvinceName | 應(MUST)/得(MAY) | 若 localityName 不存在,此欄位應(MUST)存在;否則,此欄位得(MAY)存在。若存在,應(MUST)包含主體之州或省資訊。 | 第 3.2.3 節 |
localityName | 應(MUST)/得(MAY) | 若 stateOrProvinceName 不存在,此欄位應(MUST)存在;否則,此欄位得(MAY)存在。若存在,應(MUST)包含主體之縣市地區資訊。 | 第 3.2.3 節 |
postalCode | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)包含主體之郵遞區號資訊。 | 第 3.2.3 節 |
streetAddress | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)包含主體之街道地址資訊。得(MAY)包含多個實體地址。 | 第 3.2.3 節 |
organizationName | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)包含主體之名稱及/或商業名稱/商標名稱(DBA/tradename)。CA 得(MAY)在此欄位包含與已驗證名稱略有出入之資訊,例如常見之變體或縮寫,前提是 CA 須以書面文件記錄其差異及所使用之縮寫為當地公認之縮寫。若主體之名稱與商業名稱兩者均包含,商業名稱/商標名稱應(SHALL)排列在前,其後以括號附上主體名稱。 | 第 3.2.3 節 |
surname | 應(MUST) | 主體之姓氏 | 第 3.2.3 節 |
givenName | 應(MUST) | 主體之名字 | 第 3.2.3 節 |
organizationalUnitName | 不得(MUST NOT) | - | - |
commonName | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)包含依第 7.1.4.3 節規定,取自 subjectAltName 擴充欄位之值。 | |
| 任何其他屬性 | 不建議(NOT RECOMMENDED) | - | 參見第 7.1.4.4 節 |
In addition,
subjectAttributes MUST NOT contain only metadata such as ’.’, ’-’, and ’ ’ (i.e. space) characters, and/or any other indication that the value is absent, incomplete, or not applicable.
此外,subject 屬性不得(MUST NOT)僅包含「.」、「-」及空格(space)等占位符號,及/或任何其他表示該屬性值不存在、不完整或不適用之內容。