7.1.2.7.4 已翻譯 對應原文版本:2.3.0

組織驗證型(OV)用戶憑證剖繪

跳至原文

Organization Validated

For a Subscriber Certificate to be Organization Validated, it MUST meet the following profile:

若用戶憑證屬於組織驗證型(Organization Validated)憑證,應(MUST)符合下列剖繪:

FieldRequirements
subjectSee following table.
certificatePoliciesMUST be present. MUST assert the Reserved Certificate Policy Identifier of 2.23.140.1.2.2 as a policyIdentifier. See Section 7.1.2.7.9.
All other extensionsSee Section 7.1.2.7.6
欄位要求
subject參見下表
certificatePolicies應(MUST)存在。應(MUST)使用 policyIdentifier 宣告保留憑證政策識別碼 2.23.140.1.2.2。參見第 7.1.2.7.9 節。
所有其他擴充欄位參見第 7.1.2.7.6 節

All subject names MUST be encoded as specified in Section 7.1.4.

所有 subject 名稱應(MUST)依第 7.1.4 節規定之方式編碼。

The following table details the acceptable AttributeTypes that may appear within the type field of an AttributeTypeAndValue, as well as the contents permitted within the value field.

下表列出 AttributeTypeAndValue 之 type 欄位允許使用的 AttributeType,以及對應之 value 欄位允許填列的內容。

Organization Validated subject Attributes
Attribute NamePresenceValueVerification
domainComponentMAYIf present, this field MUST contain a Domain Label from a Domain Name. The domainComponent fields for the Domain Name MUST be in a single ordered sequence containing all Domain Labels from the Domain Name. The Domain Labels MUST be encoded in the reverse order to the on-wire representation of domain names in the DNS protocol, so that the Domain Label closest to the root is encoded first. Multiple instances MAY be present.Section 3.2
countryNameMUSTThe two-letter ISO 3166-1 country code for the country associated with the Subject. If a Country is not represented by an official ISO 3166-1 country code, the CA MUST specify the ISO 3166-1 user-assigned code of XX, indicating that an official ISO 3166-1 alpha-2 code has not been assigned.Section 3.2.2.1
stateOrProvinceNameMUST / MAYMUST be present if localityName is absent, MAY be present otherwise. If present, MUST contain the Subject’s state or province information.Section 3.2.2.1
localityNameMUST / MAYMUST be present if stateOrProvinceName is absent, MAY be present otherwise. If present, MUST contain the Subject’s locality information.Section 3.2.2.1
postalCodeNOT RECOMMENDEDIf present, MUST contain the Subject’s zip or postal information.Section 3.2.2.1
streetAddressNOT RECOMMENDEDIf present, MUST contain the Subject’s street address information. Multiple instances MAY be present.Section 3.2.2.1
organizationNameMUSTThe Subject’s name and/or DBA/tradename. The CA MAY include information in this field that differs slightly from the verified name, such as common variations or abbreviations, provided that the CA documents the difference and any abbreviations used are locally accepted abbreviations; e.g. if the official record shows “Company Name Incorporated”, the CA MAY use “Company Name Inc.” or “Company Name”. If both are included, the DBA/tradename SHALL appear first, followed by the Subject’s name in parentheses.Section 3.2.2.2
surnameMUST NOT--
givenNameMUST NOT--
organizationalUnitNameMUST NOT--
commonNameNOT RECOMMENDEDIf present, MUST contain a value derived from the subjectAltName extension according to Section 7.1.4.3.
Any other attributeNOT RECOMMENDED-See Section 7.1.4.4
組織驗證型憑證之 subject 屬性
AttributeType 屬性名稱必要性value驗證方法
domainComponent得(MAY)若存在,此欄位應(MUST)包含網域名稱中之一個網域標籤(Domain Label)。該網域名稱的所有網域標籤應(MUST)以單一有序之序列表示於 domainComponent 欄位中。網域標籤應(MUST)按照與 DNS 協定之網域名稱線路傳輸(on-wire)表示相反之順序編碼,使最接近根(root)節點之網域標籤最先編碼。得(MAY)包含多個 domainComponent 實例。第 3.2 節
countryName應(MUST)與主體關聯之國家的兩字母 ISO 3166-1 國家代碼。若該國家未獲正式 ISO 3166-1 國家代碼,CA 應(MUST)指定 ISO 3166-1 使用者保留代碼 XX,以表示尚未被分配正式 ISO 3166-1 雙字母代碼。第 3.2.2.1 節
stateOrProvinceName應(MUST)/得(MAY)若 localityName 不存在,此欄位應(MUST)存在;否則,此欄位得(MAY)存在。若存在,應(MUST)包含主體之州或省資訊。第 3.2.2.1 節
localityName應(MUST)/得(MAY)若 stateOrProvinceName 不存在,此欄位應(MUST)存在;否則,此欄位得(MAY)存在。若存在,應(MUST)包含主體之縣市地區資訊。第 3.2.2.1 節
postalCode不建議(NOT RECOMMENDED)若存在,應(MUST)包含主體之郵遞區號資訊。第 3.2.2.1 節
streetAddress不建議(NOT RECOMMENDED)若存在,應(MUST)包含主體之街道地址資訊。得(MAY)包含多個實體地址。第 3.2.2.1 節
organizationName應(MUST)主體之名稱及/或商業名稱/商標名稱(DBA/tradename)。CA 得(MAY)在此欄位包含與已驗證名稱略有出入之資訊,例如常見之變體或縮寫,前提是 CA 須以書面文件記錄其差異及所使用之縮寫為當地公認之縮寫;例如:若官方記錄顯示為「Company Name Incorporated」,CA 得(MAY)使用「Company Name Inc.」或「Company Name」。若主體之名稱與商業名稱兩者均包含,商業名稱/商標名稱應(SHALL)排列在前,其後以括號附上主體名稱。第 3.2.2.2 節
surname不得(MUST NOT)--
givenName不得(MUST NOT)--
organizationalUnitName不得(MUST NOT)--
commonName不建議(NOT RECOMMENDED)若存在,應(MUST)包含依第 7.1.4.3 節規定,取自 subjectAltName 擴充欄位之值。
任何其他屬性不建議(NOT RECOMMENDED)-參見第 7.1.4.4 節

In addition, subject Attributes MUST NOT contain only metadata such as ’.’, ’-’, and ’ ’ (i.e. space) characters, and/or any other indication that the value is absent, incomplete, or not applicable.

此外,subject 屬性不得(MUST NOT)僅包含「.」、「-」及空格(space)等占位符號,及/或任何其他表示該屬性值不存在、不完整或不適用之內容。