7.1.4.2 已翻譯 對應原文版本:2.3.0

主體屬性編碼(Subject Attribute Encoding)

跳至原文

Subject Attribute Encoding

This document defines requirements for the content and validation of a number of attributes that may appear within the subject field of a tbsCertificate. CAs SHALL NOT include these attributes unless their content has been validated as specified by, and only if permitted by, the relevant certificate profile specified within Section 7.1.2.

本文件針對 tbsCertificate 的 subject 欄位中可能出現的若干屬性,定義其內容及驗證要求。除非該等屬性的內容已依第 7.1.2 節指定之相關憑證剖繪(profile)規定完成驗證,且該等屬性為該憑證剖繪所允許,否則 CA 不得(SHALL NOT)包含該等屬性。

CAs that include attributes in the Certificate subject field that are listed in the table below SHALL encode those attributes in the relative order as they appear in the table and follow the specified encoding requirements for the attribute.

若 CA 在憑證 subject 欄位中包含下表所列屬性,應(SHALL)依該等屬性於表中出現的相對順序進行編碼,並遵從各屬性的指定編碼要求。

Encoding and Order Requirements for Selected Attributes
AttributeOIDSpecificationEncoding RequirementsMax Length*
domainComponent0.9.2342.19200300.100.1.25RFC 4519MUST use IA5String63
countryName2.5.4.6RFC 5280MUST use PrintableString2
stateOrProvinceName2.5.4.8RFC 5280MUST use UTF8String or PrintableString128
localityName2.5.4.7RFC 5280MUST use UTF8String or PrintableString128
postalCode2.5.4.17X.520MUST use UTF8String or PrintableString40
streetAddress2.5.4.9X.520MUST use UTF8String or PrintableString128
organizationName2.5.4.10RFC 5280MUST use UTF8String or PrintableString64
surname2.5.4.4RFC 5280MUST use UTF8String or PrintableString641
givenName2.5.4.42RFC 5280MUST use UTF8String or PrintableString641
organizationalUnitName2.5.4.11RFC 5280MUST use UTF8String or PrintableString64
commonName2.5.4.3RFC 5280MUST use UTF8String or PrintableString64
選定屬性的編碼及順序要求
屬性OID規範編碼要求最大長度*
domainComponent0.9.2342.19200300.100.1.25RFC 4519應(MUST)使用 IA5String63
countryName2.5.4.6RFC 5280應(MUST)使用 PrintableString2
stateOrProvinceName2.5.4.8RFC 5280應(MUST)使用 UTF8String 或 PrintableString128
localityName2.5.4.7RFC 5280應(MUST)使用 UTF8String 或 PrintableString128
postalCode2.5.4.17X.520應(MUST)使用 UTF8String 或 PrintableString40
streetAddress2.5.4.9X.520應(MUST)使用 UTF8String 或 PrintableString128
organizationName2.5.4.10RFC 5280應(MUST)使用 UTF8String 或 PrintableString64
surname2.5.4.4RFC 5280應(MUST)使用 UTF8String 或 PrintableString641
givenName2.5.4.42RFC 5280應(MUST)使用 UTF8String 或 PrintableString641
organizationalUnitName2.5.4.11RFC 5280應(MUST)使用 UTF8String 或 PrintableString64
commonName2.5.4.3RFC 5280應(MUST)使用 UTF8String 或 PrintableString64

* Note: ASN.1 length limits for DirectoryString are expressed as character limits, not byte limits.

* 注意:DirectoryString 的 ASN.1 長度限制是以字元數計,而非位元組數。

CAs that include attributes in the Certificate subject field that are listed in the table below SHALL follow the specified encoding requirements for the attribute.

若 CA 在憑證 subject 欄位中包含下表所列屬性,應(SHALL)遵從各屬性的指定編碼要求。

Encoding Requirements for Selected Attributes
AttributeOIDSpecificationEncoding RequirementsMax Length*
businessCategory2.5.4.15X.520MUST use UTF8String or PrintableString128
jurisdictionCountry1.3.6.1.4.1.311.60.2.1.3Guidelines for the Issuance and Management of Extended Validation CertificatesMUST use PrintableString2
jurisdictionStateOrProvince1.3.6.1.4.1.311.60.2.1.2Guidelines for the Issuance and Management of Extended Validation CertificatesMUST use UTF8String or PrintableString128
jurisdictionLocality1.3.6.1.4.1.311.60.2.1.1Guidelines for the Issuance and Management of Extended Validation CertificatesMUST use UTF8String or PrintableString128
serialNumber2.5.4.5RFC 5280MUST use PrintableString64
organizationIdentifier2.5.4.97X.520MUST use UTF8String or PrintableStringNone
選定屬性的編碼要求
屬性OID規範編碼要求最大長度*
businessCategory2.5.4.15X.520應(MUST)使用 UTF8String 或 PrintableString128
jurisdictionCountry1.3.6.1.4.1.311.60.2.1.3《延伸驗證型憑證之簽發與管理指引》(Guidelines for the Issuance and Management of Extended Validation Certificates)應(MUST)使用 PrintableString2
jurisdictionStateOrProvince1.3.6.1.4.1.311.60.2.1.2《延伸驗證型憑證之簽發與管理指引》(Guidelines for the Issuance and Management of Extended Validation Certificates)應(MUST)使用 UTF8String 或 PrintableString128
jurisdictionLocality1.3.6.1.4.1.311.60.2.1.1《延伸驗證型憑證之簽發與管理指引》(Guidelines for the Issuance and Management of Extended Validation Certificates)應(MUST)使用 UTF8String 或 PrintableString128
serialNumber2.5.4.5RFC 5280應(MUST)使用 PrintableString64
organizationIdentifier2.5.4.97X.520應(MUST)使用 UTF8String 或 PrintableString無限制

* Note: ASN.1 length limits for DirectoryString are expressed as character limits, not byte limits.

* 注意:DirectoryString 的 ASN.1 長度限制是以字元數計,而非位元組數。

註腳

  1. Note: Although RFC 5280 specifies the upper bound as 32,768 characters, this was a transcription error from X.520 (08/2005). The effective (interoperable) upper bound is 64 characters. ↩ ↩2

  2. 注意:雖然 RFC 5280 規定上限為 32,768 個字元,但此係轉錄 X.520(2005 年 8 月版)時所產生之筆誤。有效(可交互運作)的上限為 64 個字元。 ↩ ↩2