7.1.2.7 已翻譯 對應原文版本:2.3.0
用戶(伺服器)(Subscriber (Server))憑證剖繪
Subscriber (Server) Certificate Profile
Field Description tbsCertificateversionMUST be v3(2) serialNumberMUST be a non-sequential number greater than zero (0) and less than 2¹⁵⁹ containing at least 64 bits of output from a CSPRNG. signatureSee Section 7.1.3.2 issuerMUST be byte-for-byte identical to the subjectfield of the Issuing CA. See Section 7.1.4.1validitynotBeforeA value within 48 hours of the certificate signing operation. notAfterSee Section 6.3.2 subjectSee Section 7.1.2.7.1 subjectPublicKeyInfoSee Section 7.1.3.1 issuerUniqueIDMUST NOT be present subjectUniqueIDMUST NOT be present extensionsSee Section 7.1.2.7.6 signatureAlgorithmEncoded value MUST be byte-for-byte identical to the tbsCertificate.signature.signature
| 欄位 | 說明 |
|---|---|
tbsCertificate | |
version | 應(MUST)為 v3(2) |
serialNumber | 應(MUST)為一個非連續之數值,其值大於 0 且小於 2¹⁵⁹,且其中至少 64 個位元應來自 CSPRNG 之輸出。 |
signature | 參見第 7.1.3.2 節 |
issuer | 應(MUST)與簽發憑證機構(Issuing CA)之 subject 欄位逐位元組完全相同。參見第 7.1.4.1 節 |
validity | |
notBefore | 與憑證簽章作業時間點相差不超過 48 小時之值。 |
notAfter | 參見第 6.3.2 節 |
subject | 參見第 7.1.2.7.1 節 |
subjectPublicKeyInfo | 參見第 7.1.3.1 節 |
issuerUniqueID | 不得(MUST NOT)存在 |
subjectUniqueID | 不得(MUST NOT)存在 |
extensions | 參見第 7.1.2.7.6 節 |
signatureAlgorithm | 編碼後之值應(MUST)與 tbsCertificate.signature 逐位元組完全相同 |
signature |