7.1.2.7.7 已翻譯 對應原文版本:2.3.0

用戶憑證(Subscriber Certificate)之憑證機構資訊存取(Authority Information Access)

跳至原文

Subscriber Certificate Authority Information Access

The AuthorityInfoAccessSyntax MUST contain one or more AccessDescriptions. Each AccessDescription MUST only contain a permitted accessMethod, as detailed below, and each accessLocation MUST be encoded as the specified GeneralName type.

AuthorityInfoAccessSyntax 應(MUST)包含一個或多個 AccessDescription。每個 AccessDescription 應(MUST)僅包含下表所列之允許 accessMethod,且每個 accessLocation 應(MUST)編碼為指定之 GeneralName 型別。

The AuthorityInfoAccessSyntax MAY contain multiple AccessDescriptions with the same accessMethod, if permitted for that accessMethod. When multiple AccessDescriptions are present with the same accessMethod, each accessLocation MUST be unique, and each AccessDescription MUST be ordered in priority for that accessMethod, with the most-preferred accessLocation being the first AccessDescription. No ordering requirements are given for AccessDescriptions that contain different accessMethods, provided that previous requirement is satisfied.

若該 accessMethod 允許指定多個 AccessDescription,AuthorityInfoAccessSyntax 得(MAY)包含多個具有相同 accessMethod 的 AccessDescription。當存在多個具有相同 accessMethod 的 AccessDescription 時,各 accessLocation 應(MUST)互不相同,且各 AccessDescription 應(MUST)依該 accessMethod 之優先順位排列,其中具有最高優先順位 accessLocation 的 AccessDescription 應排列於首位。在符合前述要求之前提下,對於具有不同 accessMethod 的 AccessDescription,不另定其排序要求。

Access MethodAccess LocationPresenceMaximumDescription
id-ad-ocsp (OID: 1.3.6.1.5.5.7.48.1)uniformResourceIdentifierMAY*A HTTP URL of the Issuing CA’s OCSP responder.
id-ad-caIssuers (OID: 1.3.6.1.5.5.7.48.2)uniformResourceIdentifierSHOULD*A HTTP URL of the Issuing CA’s certificate.
Any other value-MUST NOT-No other accessMethods may be used.
accessMethodaccessLocation必要性最大數量說明
id-ad-ocsp(OID:1.3.6.1.5.5.7.48.1)uniformResourceIdentifier得(MAY)*(任意數量)簽發憑證機構(Issuing CA)的 OCSP 回應伺服器 HTTP URL。
id-ad-caIssuers(OID:1.3.6.1.5.5.7.48.2)uniformResourceIdentifier宜(SHOULD)*(任意數量)簽發憑證機構憑證的 HTTP URL。
任何其他值-不得(MUST NOT)-不得使用其他 accessMethod。