7.1.2.8.8 已翻譯 對應原文版本:2.3.0

OCSP 回應伺服器(OCSP Responder)之憑證原則(Certificate Policies)

跳至原文

OCSP Responder Certificate Policies

If present, the Certificate Policies extension MUST contain at least one PolicyInformation. Each PolicyInformation MUST match the following profile:

若存在,憑證原則(Certificate Policies)擴充欄位應(MUST)包含至少一個 PolicyInformation。每個 PolicyInformation 應(MUST)符合下列剖繪:

FieldPresenceContents
policyIdentifierMUSTOne of the following policy identifiers:
A Reserved Certificate Policy IdentifierNOT RECOMMENDED
anyPolicyNOT RECOMMENDED
Any other identifierNOT RECOMMENDEDIf present, MUST be defined by the CA and documented by the CA in its Certificate Policy and/or Certification Practice Statement.
policyQualifiersNOT RECOMMENDEDIf present, MUST contain only permitted policyQualifiers from the table below.
欄位必要性內容
policyIdentifier應(MUST)下列政策識別碼之一:
保留憑證政策識別碼不建議(NOT RECOMMENDED)
anyPolicy不建議(NOT RECOMMENDED)
任何其他識別碼不建議(NOT RECOMMENDED)若存在,應(MUST)由 CA 定義,並載明於其憑證政策(CP)及/或憑證實務作業基準(CPS)中。
policyQualifiers不建議(NOT RECOMMENDED)若存在,應(MUST)僅包含下表所列之允許 policyQualifiers。
Permitted policyQualifiers
Qualifier IDPresenceField TypeContents
id-qt-cps (OID: 1.3.6.1.5.5.7.2.1)MAYIA5StringThe HTTP or HTTPS URL for the Issuing CA’s Certificate Policies, Certification Practice Statement, Relying Party Agreement, or other pointer to online policy information provided by the Issuing CA.
Any other qualifierMUST NOT--
允許之 policyQualifiers
Qualifier ID必要性欄位型別內容
id-qt-cps(OID:1.3.6.1.5.5.7.2.1)得(MAY)IA5String簽發憑證機構(Issuing CA)之憑證政策(CP)、憑證實務作業基準(CPS)、信賴憑證者協議(Relying Party Agreement),或其他由簽發憑證機構提供的線上政策資訊之 HTTP 或 HTTPS URL。
任何其他 qualifier不得(MUST NOT)--

Note: Because the Certificate Policies extension may be used to restrict the applicable usages for a Certificate, incorrect policies may result in OCSP Responder Certificates that fail to successfully validate, resulting in invalid OCSP Responses. Including the anyPolicy policy can reduce this risk, but add to client processing complexity and interoperability issues.

注意:由於憑證原則擴充欄位可用於限制憑證的適用用途,若憑證原則設定不正確,可能導致 OCSP 回應伺服器憑證無法通過驗證,進而造成 OCSP 回應無效。包含 anyPolicy 政策識別碼可降低此風險,但會增加用戶端處理的複雜度,並可能造成交互運作問題。