7.2.2 已翻譯 對應原文版本:2.3.0

憑證廢止清冊(CRL)及 CRL 條目之擴充欄位

跳至原文

CRL and CRL entry extensions

CRL Extensions
ExtensionPresenceCriticalDescription
authorityKeyIdentifierMUSTNSee Section 7.1.2.11.1
CRLNumberMUSTNMUST contain an INTEGER greater than or equal to zero (0) and less than 2¹⁵⁹, and convey a strictly increasing sequence.
IssuingDistributionPoint*YSee Section 7.2.2.1 CRL Issuing Distribution Point
Any other extensionNOT RECOMMENDED--
CRL 擴充欄位
擴充欄位必要性關鍵性說明
authorityKeyIdentifier應(MUST)N參見第 7.1.2.11.1 節。
CRLNumber應(MUST)N應(MUST)包含一個大於或等於 0 且小於 2¹⁵⁹ 之整數(INTEGER),且該整數與其他 CRLNumber 形成嚴格遞增序列。
IssuingDistributionPoint*Y參見第 7.2.2.1 節 憑證廢止清冊(CRL)簽發發布點
其他任何擴充欄位不建議(NOT RECOMMENDED)--
revokedCertificates Component
ComponentPresenceDescription
serialNumberMUSTMUST be byte-for-byte identical to the serialNumber contained in the revoked Certificate.
revocationDateMUSTNormally, the date and time revocation occurred. See the footnote following this table for circumstances where backdating is permitted.
crlEntryExtensions*See the “crlEntryExtensions Component” table for additional requirements.
revokedCertificates 元件
元件必要性說明
serialNumber應(MUST)應(MUST)與已廢止憑證的 serialNumber 逐位元組完全相同
revocationDate應(MUST)通常為執行廢止作業的日期及時間。允許倒填日期(backdating)之情形,詳見本表下方注意內容。
crlEntryExtensions*其他要求詳見「crlEntryExtensions 元件」表格

Note: The CA SHOULD update the revocation date in a CRL entry when it is determined that the private key of the Certificate was compromised prior to the revocation date that is indicated in the CRL entry for that Certificate. Backdating the revocationDate field is an exception to best practice described in RFC 5280, Section 5.3.2; however, these requirements specify the use of the revocationDate field to support TLS implementations that process the revocationDate field as the date when the Certificate is first considered to be compromised.

注意:若確定憑證的私密金鑰(Private Key)在該憑證的 CRL 條目所載之廢止日期前即已遭破解(compromise),CA 宜(SHOULD)更新該 CRL 條目中的廢止日期。倒填 revocationDate 欄位屬於 RFC 5280 第 5.3.2 節 所述最佳實務之例外;然而,本節要求指定使用 revocationDate 欄位,以支援將該欄位所載日期視為憑證首次被認定已遭破解之日期的 TLS 實作。

crlEntryExtensions Component
CRL Entry ExtensionPresenceDescription
reasonCode*When present (OID 2.5.29.21), MUST NOT be marked critical and MUST indicate the most appropriate reason for revocation of the Certificate.

MUST be present unless the CRL entry is for a Certificate not technically capable of causing issuance and either 1) the CRL entry is for a Subscriber Certificate subject to these Requirements revoked prior to 2023-07-15 or 2) the reason for revocation (i.e., reasonCode) is unspecified (0).

See the “CRLReasons” table for additional requirements.
Any other valueNOT RECOMMENDED-
crlEntryExtensions 元件
CRL 條目擴充欄位必要性說明
reasonCode*若存在(OID 2.5.29.21),不得(MUST NOT)標記為關鍵(critical),且應(MUST)指出廢止該憑證之最適當原因。

除非該 CRL 條目對應之憑證在技術上不具備執行憑證簽發的能力,且符合下列情形之一,否則 reasonCode 應(MUST)存在:(1)該 CRL 條目對應的是受《基本要求》規範,且於 2023-07-15 之前遭廢止的用戶憑證;或(2)廢止原因(即 reasonCode)為 unspecified (0)。

其他要求詳見「CRLReasons」表格。
其他任何值不建議(NOT RECOMMENDED)-
CRLReasons
RFC 5280 reasonCodeRFC 5280 reasonCode valueDescription
unspecified0Represented by the omission of a reasonCode. MUST be omitted if the CRL entry is for a Certificate not technically capable of causing issuance unless the CRL entry is for a Subscriber Certificate subject to these Requirements revoked prior to 2023-07-15.
keyCompromise1Indicates that it is known or suspected that the Subscriber’s Private Key has been compromised.
affiliationChanged3Indicates that the Subject’s name or other Subject Identity Information in the Certificate has changed, but there is no cause to suspect that the Certificate’s Private Key has been compromised.
superseded4Indicates that the Certificate is being replaced because: the Subscriber has requested a new Certificate, the CA has reasonable evidence that the validation of domain authorization or control for any fully-qualified domain name or IP address in the Certificate should not be relied upon, or the CA has revoked the Certificate for compliance reasons such as the Certificate does not comply with these Baseline Requirements or the CA’s CP or CPS.
cessationOfOperation5Indicates that the website with the Certificate is shut down prior to the expiration of the Certificate, or if the Subscriber no longer owns or controls the Domain Name in the Certificate prior to the expiration of the Certificate.
certificateHold6MUST NOT be included if the CRL entry is for 1) a Certificate subject to these Requirements, or 2) a Certificate not subject to these Requirements and was either A) issued on-or-after 2020-09-30 or B) has a notBefore on-or-after 2020-09-30.
privilegeWithdrawn9Indicates that there has been a subscriber-side infraction that has not resulted in keyCompromise, such as the Certificate Subscriber provided misleading information in their Certificate Request or has not upheld their material obligations under the Subscriber Agreement or Terms of Use.
CRLReasons
RFC 5280 reasonCodeRFC 5280 reasonCode 值說明
unspecified0以省略 reasonCode 表示。若 CRL 條目對應之憑證在技術上不具備執行憑證簽發的能力,則應(MUST)省略 reasonCode,除非該 CRL 條目對應的是受《基本要求》規範,且於 2023-07-15 之前遭廢止的用戶憑證。
keyCompromise1表示已知或疑似用戶的私密金鑰已遭破解(compromised)。
affiliationChanged3表示憑證中的主體名稱(Subject’s name)或其他主體識別資訊(Subject Identity Information)已變更,但無理由懷疑該憑證的私密金鑰已遭破解。
superseded4表示憑證因下列原因而被取代:用戶已申請新憑證;CA 有合理證據認為,憑證中任一完全吻合網域名稱(FQDN)或 IP 位址的網域授權或控管權驗證不應再受信賴;或 CA 基於符合規範原因而廢止該憑證,例如憑證不遵循本《基本要求》或 CA 的憑證政策(CP)或憑證實務作業基準(CPS)之規定。
cessationOfOperation5表示使用該憑證的網站於憑證有效期屆滿前停止運作,或用戶於憑證有效期屆滿前不再擁有或控管該憑證中的網域名稱(Domain Name)。
certificateHold6若 CRL 條目所對應的是下列任一憑證,則不得(MUST NOT)包含 certificateHold:(1)受《基本要求》規範之憑證;或(2)不受《基本要求》規範,且符合下列任一情形之憑證:(A)於 2020-09-30 當日或之後簽發;或(B)其 notBefore 為 2020-09-30 當日或之後。
privilegeWithdrawn9表示用戶方發生違規情形,但未導致金鑰遭破解(keyCompromise),例如憑證用戶在憑證申請(Certificate Request)中提供誤導性資訊,或未履行用戶協議(Subscriber Agreement)或使用條款(Terms of Use)所定之重大義務。

The Subscriber Agreement, or an online resource referenced therein, MUST inform Subscribers about the revocation reason options listed above and provide explanation about when to choose each option. Tools that the CA provides to the Subscriber MUST allow for these options to be easily specified when the Subscriber requests revocation of their Certificate, with the default value being that no revocation reason is provided (i.e. the default corresponds to the CRLReason “unspecified (0)” which results in no reasonCode extension being provided in the CRL).

用戶協議(Subscriber Agreement)或其中所參照的線上資源,應(MUST)告知用戶上述的廢止原因選項,並說明各選項應於何種情形下選用。CA 提供給用戶的工具,應(MUST)允許用戶於請求廢止其憑證時,能輕易指定上述的選項;其預設值應為不提供廢止原因(即預設值對應於 CRLReason「unspecified (0)」,因此 CRL 中不提供 reasonCode 擴充欄位)。

The privilegeWithdrawn reasonCode SHOULD NOT be made available to the Subscriber as a revocation reason option, because the use of this reasonCode is determined by the CA and not the Subscriber.

privilegeWithdrawn reasonCode 不宜(SHOULD NOT)作為供用戶選擇的廢止原因選項,因為是否使用此 reasonCode 是由 CA 決定,而非由用戶決定。

When a CA obtains verifiable evidence of Key Compromise for a Certificate whose CRL entry does not contain a reasonCode extension or has a reasonCode extension with a non-keyCompromise reason, the CA SHOULD update the CRL entry to enter keyCompromise as the CRLReason in the reasonCode extension.

若 CA 取得某憑證金鑰遭破解(Key Compromise)的可查證證據,而該憑證的 CRL 條目不含 reasonCode 擴充欄位,或其 reasonCode 擴充欄位所載原因並非 keyCompromise,則 CA 宜(SHOULD)更新該 CRL 條目,將 reasonCode 擴充欄位中的 CRLReason 設為 keyCompromise。