用戶憑證(Subscriber Certificate)之憑證原則(Certificate Policies)
Subscriber Certificate Certificate Policies
If present, the Certificate Policies extension MUST contain at least one
PolicyInformation. EachPolicyInformationMUST match the following profile:
若存在,憑證原則(Certificate Policies)擴充欄位應(MUST)包含至少一個 PolicyInformation。每個 PolicyInformation 應(MUST)符合下列剖繪:
Field Presence Contents policyIdentifierMUST One of the following policy identifiers: A Reserved Certificate Policy Identifier MUST The Reserved Certificate Policy Identifier (see Section 7.1.6.1) associated with the given Subscriber Certificate type (see Section 7.1.2.7.1). anyPolicyMUST NOT The anyPolicyPolicy Identifier MUST NOT be present.Any other identifier MAY If present, MUST be defined and documented in the CA’s Certificate Policy and/or Certification Practice Statement. policyQualifiersNOT RECOMMENDED If present, MUST contain only permitted policyQualifiersfrom the table below.
| 欄位 | 必要性 | 內容 |
|---|---|---|
policyIdentifier | 應(MUST) | 下列政策識別碼之一: |
| 保留憑證政策識別碼 | 應(MUST) | 與指定用戶憑證類型(參見第 7.1.2.7.1 節)相對應之保留憑證政策識別碼(參見第 7.1.6.1 節)。 |
anyPolicy | 不得(MUST NOT) | anyPolicy 政策識別碼不得(MUST NOT)存在。 |
| 任何其他識別碼 | 得(MAY) | 若存在,應(MUST)由 CA 定義,並載明於其憑證政策(CP)及/或憑證實務作業基準(CPS)中。 |
policyQualifiers | 不建議(NOT RECOMMENDED) | 若存在,應(MUST)僅包含下表所列之允許 policyQualifiers。 |
This Profile RECOMMENDS that the first
PolicyInformationvalue within the Certificate Policies extension contains the Reserved Certificate Policy Identifier (see 7.1.6.1)1. Regardless of the order ofPolicyInformationvalues, the Certificate Policies extension MUST contain exactly one Reserved Certificate Policy Identifier.
本剖繪建議(RECOMMENDED)憑證原則擴充欄位中之第一個 PolicyInformation 值包含保留憑證政策識別碼(參見第 7.1.6.1 節)1。無論 PolicyInformation 值之順序為何,憑證原則擴充欄位應(MUST)包含僅有一個保留憑證政策識別碼。
Permitted policyQualifiersQualifier ID Presence Field Type Contents id-qt-cps(OID: 1.3.6.1.5.5.7.2.1)MAY IA5StringThe HTTP or HTTPS URL for the Issuing CA’s Certificate Policies, Certification Practice Statement, Relying Party Agreement, or other pointer to online policy information provided by the Issuing CA. Any other qualifier MUST NOT - -
| Qualifier ID | 必要性 | 欄位型別 | 內容 |
|---|---|---|---|
id-qt-cps(OID:1.3.6.1.5.5.7.2.1) | 得(MAY) | IA5String | 簽發憑證機構(Issuing CA)之憑證政策(CP)、憑證實務作業基準(CPS)、信賴憑證者協議(Relying Party Agreement),或其他由簽發憑證機構提供的線上政策資訊之 HTTP 或 HTTPS URL。 |
| 任何其他 qualifier | 不得(MUST NOT) | - | - |
註腳
-
Although RFC 5280 allows
PolicyInformations to appear in any order, several client implementations have implemented logic that considers thepolicyIdentifierthat matches a given filter. As such, ensuring the Reserved Certificate Policy Identifier is the firstPolicyInformationreduces the risk of interoperability challenges. ↩ -
雖然 RFC 5280 允許
PolicyInformation以任意順序出現,但部分用戶端實作所採用的程式邏輯會考量符合特定篩選條件的policyIdentifier。因此,確保含有保留憑證政策識別碼(Reserved Certificate Policy Identifier)之PolicyInformation位於首位,可降低發生交互運作問題之風險。 ↩