7.1.2.8 已翻譯 對應原文版本:2.3.0

OCSP 回應伺服器(OCSP Responder)憑證剖繪

跳至原文

OCSP Responder Certificate Profile

If the Issuing CA does not directly sign OCSP responses, it MAY make use of an OCSP Authorized Responder, as defined by RFC 6960, Section 4.2.2.2. The Issuing CA of the Responder MUST be the same as the Issuing CA for the Certificates it provides responses for.

若簽發憑證機構(Issuing CA)不直接簽章 OCSP 回應,得(MAY)使用 RFC 6960 第 4.2.2.2 節 所定義之 OCSP 授權回應伺服器(OCSP Authorized Responder)。該回應伺服器的簽發憑證機構(Issuing CA of the Responder)應(MUST)與回應伺服器所提供的 OCSP 回應之憑證的簽發憑證機構(Issuing CA)相同。

FieldDescription
tbsCertificate
versionMUST be v3(2)
serialNumberMUST be a non-sequential number greater than zero (0) and less than 2¹⁵⁹ containing at least 64 bits of output from a CSPRNG.
signatureSee Section 7.1.3.2
issuerMUST be byte-for-byte identical to the subject field of the Issuing CA. See Section 7.1.4.1
validitySee Section 7.1.2.8.1
subjectSee Section 7.1.2.10.2
subjectPublicKeyInfoSee Section 7.1.3.1
issuerUniqueIDMUST NOT be present
subjectUniqueIDMUST NOT be present
extensionsSee Section 7.1.2.8.2
signatureAlgorithmEncoded value MUST be byte-for-byte identical to the tbsCertificate.signature.
signature
欄位說明
tbsCertificate
version應(MUST)為 v3(2)
serialNumber應(MUST)為一個非連續之數值,其值大於 0 且小於 2¹⁵⁹,且其中至少 64 個位元應來自 CSPRNG 之輸出。
signature參見第 7.1.3.2 節
issuer應(MUST)與簽發憑證機構(Issuing CA)之 subject 欄位逐位元組完全相同。參見第 7.1.4.1 節
validity參見第 7.1.2.8.1 節
subject參見第 7.1.2.10.2 節
subjectPublicKeyInfo參見第 7.1.3.1 節
issuerUniqueID不得(MUST NOT)存在
subjectUniqueID不得(MUST NOT)存在
extensions參見第 7.1.2.8.2 節
signatureAlgorithm編碼後之值應(MUST)與 tbsCertificate.signature 逐位元組完全相同
signature