主體屬性編碼(Subject Attribute Encoding)
Subject Attribute Encoding
This document defines requirements for the content and validation of a number of attributes that may appear within the
subjectfield of atbsCertificate. CAs SHALL NOT include these attributes unless their content has been validated as specified by, and only if permitted by, the relevant certificate profile specified within Section 7.1.2.
本文件針對 tbsCertificate 的 subject 欄位中可能出現的若干屬性,定義其內容及驗證要求。除非該等屬性的內容已依第 7.1.2 節指定之相關憑證剖繪(profile)規定完成驗證,且該等屬性為該憑證剖繪所允許,否則 CA 不得(SHALL NOT)包含該等屬性。
CAs that include attributes in the Certificate
subjectfield that are listed in the table below SHALL encode those attributes in the relative order as they appear in the table and follow the specified encoding requirements for the attribute.
若 CA 在憑證 subject 欄位中包含下表所列屬性,應(SHALL)依該等屬性於表中出現的相對順序進行編碼,並遵從各屬性的指定編碼要求。
Encoding and Order Requirements for Selected Attributes Attribute OID Specification Encoding Requirements Max Length* domainComponent0.9.2342.19200300.100.1.25 RFC 4519 MUST use IA5String63 countryName2.5.4.6 RFC 5280 MUST use PrintableString2 stateOrProvinceName2.5.4.8 RFC 5280 MUST use UTF8StringorPrintableString128 localityName2.5.4.7 RFC 5280 MUST use UTF8StringorPrintableString128 postalCode2.5.4.17 X.520 MUST use UTF8StringorPrintableString40 streetAddress2.5.4.9 X.520 MUST use UTF8StringorPrintableString128 organizationName2.5.4.10 RFC 5280 MUST use UTF8StringorPrintableString64 surname2.5.4.4 RFC 5280 MUST use UTF8StringorPrintableString641 givenName2.5.4.42 RFC 5280 MUST use UTF8StringorPrintableString641 organizationalUnitName2.5.4.11 RFC 5280 MUST use UTF8StringorPrintableString64 commonName2.5.4.3 RFC 5280 MUST use UTF8StringorPrintableString64
| 屬性 | OID | 規範 | 編碼要求 | 最大長度* |
|---|---|---|---|---|
domainComponent | 0.9.2342.19200300.100.1.25 | RFC 4519 | 應(MUST)使用 IA5String | 63 |
countryName | 2.5.4.6 | RFC 5280 | 應(MUST)使用 PrintableString | 2 |
stateOrProvinceName | 2.5.4.8 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 128 |
localityName | 2.5.4.7 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 128 |
postalCode | 2.5.4.17 | X.520 | 應(MUST)使用 UTF8String 或 PrintableString | 40 |
streetAddress | 2.5.4.9 | X.520 | 應(MUST)使用 UTF8String 或 PrintableString | 128 |
organizationName | 2.5.4.10 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 64 |
surname | 2.5.4.4 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 641 |
givenName | 2.5.4.42 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 641 |
organizationalUnitName | 2.5.4.11 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 64 |
commonName | 2.5.4.3 | RFC 5280 | 應(MUST)使用 UTF8String 或 PrintableString | 64 |
* Note: ASN.1 length limits for DirectoryString are expressed as character limits, not byte limits.
* 注意:DirectoryString 的 ASN.1 長度限制是以字元數計,而非位元組數。
CAs that include attributes in the Certificate
subjectfield that are listed in the table below SHALL follow the specified encoding requirements for the attribute.
若 CA 在憑證 subject 欄位中包含下表所列屬性,應(SHALL)遵從各屬性的指定編碼要求。
Encoding Requirements for Selected Attributes Attribute OID Specification Encoding Requirements Max Length* businessCategory2.5.4.15 X.520 MUST use UTF8StringorPrintableString128 jurisdictionCountry1.3.6.1.4.1.311.60.2.1.3 Guidelines for the Issuance and Management of Extended Validation Certificates MUST use PrintableString2 jurisdictionStateOrProvince1.3.6.1.4.1.311.60.2.1.2 Guidelines for the Issuance and Management of Extended Validation Certificates MUST use UTF8StringorPrintableString128 jurisdictionLocality1.3.6.1.4.1.311.60.2.1.1 Guidelines for the Issuance and Management of Extended Validation Certificates MUST use UTF8StringorPrintableString128 serialNumber2.5.4.5 RFC 5280 MUST use PrintableString64 organizationIdentifier2.5.4.97 X.520 MUST use UTF8StringorPrintableStringNone
| 屬性 | OID | 規範 | 編碼要求 | 最大長度* |
|---|---|---|---|---|
businessCategory | 2.5.4.15 | X.520 | 應(MUST)使用 UTF8String 或 PrintableString | 128 |
jurisdictionCountry | 1.3.6.1.4.1.311.60.2.1.3 | 《延伸驗證型憑證之簽發與管理指引》(Guidelines for the Issuance and Management of Extended Validation Certificates) | 應(MUST)使用 PrintableString | 2 |
jurisdictionStateOrProvince | 1.3.6.1.4.1.311.60.2.1.2 | 《延伸驗證型憑證之簽發與管理指引》(Guidelines for the Issuance and Management of Extended Validation Certificates) | 應(MUST)使用 UTF8String 或 PrintableString | 128 |
jurisdictionLocality | 1.3.6.1.4.1.311.60.2.1.1 | 《延伸驗證型憑證之簽發與管理指引》(Guidelines for the Issuance and Management of Extended Validation Certificates) | 應(MUST)使用 UTF8String 或 PrintableString | 128 |
serialNumber | 2.5.4.5 | RFC 5280 | 應(MUST)使用 PrintableString | 64 |
organizationIdentifier | 2.5.4.97 | X.520 | 應(MUST)使用 UTF8String 或 PrintableString | 無限制 |
* Note: ASN.1 length limits for DirectoryString are expressed as character limits, not byte limits.
* 注意:DirectoryString 的 ASN.1 長度限制是以字元數計,而非位元組數。