OCSP 回應伺服器(OCSP Responder)之基本限制(Basic Constraints)
OCSP Responder Basic Constraints
OCSP Responder certificates MUST NOT be CA certificates. The issuing CA may indicate this one of two ways: by omission of the
basicConstraintsextension, or through the inclusion of abasicConstraintsextension that sets thecAboolean to FALSE.
OCSP 回應伺服器憑證不得(MUST NOT)為 CA 憑證。簽發憑證機構(issuing CA)得以下列兩種方式之一表明該憑證非 CA 憑證:不包含 basicConstraints 擴充欄位,或包含將 cA 布林值設為 FALSE 的 basicConstraints 擴充欄位。
Field Description cAMUST be FALSE pathLenConstraintMUST NOT be present
| 欄位 | 說明 |
|---|---|
cA | 應(MUST)為 FALSE |
pathLenConstraint | 不得(MUST NOT)存在 |
Note: Due to DER encoding rules regarding the encoding of DEFAULT values within OPTIONAL fields, a
basicConstraintsextension that sets thecAboolean to FALSE MUST have anextnValueOCTET STRINGwhich is exactly the hex-encoded bytes3000, the encoded representation of an empty ASN.1SEQUENCEvalue.
注意:依 DER 對 OPTIONAL 欄位中 DEFAULT 值之編碼規則,將 cA 布林值設為 FALSE 的 basicConstraints 擴充欄位,其 extnValue OCTET STRING 內容應(MUST)確切為十六進位編碼之位元組 3000,即空 ASN.1 SEQUENCE 值之編碼表示。