7.3 已翻譯 對應原文版本:2.3.0

線上憑證狀態協定(OCSP)剖繪

跳至原文

OCSP profile

If an OCSP response is for a Root CA or Subordinate CA Certificate, including Cross-Certified Subordinate CA Certificates, and that certificate has been revoked, then the revocationReason field within the RevokedInfo of the CertStatus MUST be present.

若線上憑證狀態協定(Online Certificate Status Protocol,OCSP)回應是針對根憑證機構(Root CA)憑證或下屬憑證機構(Subordinate CA)憑證(包括交互認證之下屬憑證機構憑證),且該憑證已遭廢止,則 CertStatus 之 RevokedInfo 中的 revocationReason 欄位應(MUST)存在。

The CRLReason indicated MUST contain a value permitted for CRLs, as specified in Section 7.2.2.

所指定的 CRLReason 應(MUST)包含第 7.2.2 節規定可用於 CRL 的值。