9.6.1 已翻譯 對應原文版本:2.3.0

憑證機構(CA)之聲明與擔保

跳至原文

CA representations and warranties

By issuing a Certificate, the CA makes the certificate warranties listed herein to the following Certificate Beneficiaries:

  1. The Subscriber that is a party to the Subscriber Agreement or Terms of Use for the Certificate;
  2. All Application Software Suppliers with whom the Root CA has entered into a contract for inclusion of its Root Certificate in software distributed by such Application Software Supplier; and
  3. All Relying Parties who reasonably rely on a Valid Certificate.

憑證機構(Certification Authority,CA)藉由簽發憑證,向下列憑證受益人(Certificate Beneficiaries)作出本節所列之憑證擔保:

  1. 憑證的用戶協議(Subscriber Agreement)或使用條款(Terms of Use)中為當事方之用戶;
  2. 與根憑證機構(Root CA)締結契約,約定將該根憑證機構之根憑證納入其所發行軟體的所有應用軟體供應商(Application Software Supplier);及
  3. 合理信賴有效憑證的所有信賴憑證者(Relying Party)。

The CA represents and warrants to the Certificate Beneficiaries that, during the period when the Certificate is valid, the CA has complied with these Requirements and its Certificate Policy and/or Certification Practice Statement in issuing and managing the Certificate.

CA 向憑證受益人聲明及擔保,在憑證有效期內,CA 於簽發及管理該憑證時,遵循本文件要求規定及其憑證政策(CP)及/或憑證實務作業基準(CPS)。

The Certificate Warranties specifically include, but are not limited to, the following:

  1. Right to Use Domain Name or IP Address: That, at the time of issuance, the CA

    1. implemented a procedure for verifying that the Applicant either had the right to use, or had control of, the Domain Name(s) and IP address(es) listed in the Certificate’s subject field and subjectAltName extension (or, only in the case of Domain Names, was delegated such right or control by someone who had such right to use or control);
    2. followed the procedure when issuing the Certificate; and
    3. accurately described the procedure in the CA’s Certificate Policy and/or Certification Practice Statement;
  2. Authorization for Certificate: That, at the time of issuance, the CA

    1. implemented a procedure for verifying that the Subject authorized the issuance of the Certificate and that the Applicant Representative is authorized to request the Certificate on behalf of the Subject;
    2. followed the procedure when issuing the Certificate; and
    3. accurately described the procedure in the CA’s Certificate Policy and/or Certification Practice Statement;
  3. Accuracy of Information: That, at the time of issuance, the CA

    1. implemented a procedure for verifying the accuracy of all of the information contained in the Certificate;
    2. followed the procedure when issuing the Certificate; and
    3. accurately described the procedure in the CA’s Certificate Policy and/or Certification Practice Statement;
  4. Identity of Applicant: That, if the Certificate contains Subject Identity Information, the CA

    1. implemented a procedure to verify the identity of the Applicant in accordance with Section 3.2 and Section 7.1.2;
    2. followed the procedure when issuing the Certificate; and
    3. accurately described the procedure in the CA’s Certificate Policy and/or Certification Practice Statement;
  5. Subscriber Agreement: That, if the CA and Subscriber are not Affiliated, the Subscriber and CA are parties to a legally valid and enforceable Subscriber Agreement that satisfies these Requirements, or, if the CA and Subscriber are the same entity or are Affiliated, the Applicant Representative acknowledged the Terms of Use;

  6. Status: That the CA maintains a 24 x 7 publicly-accessible Repository with current information regarding the status (valid or revoked) of all unexpired Certificates; and

  7. Revocation: That the CA will revoke the Certificate for any of the reasons specified in these Requirements.

憑證擔保具體包括(但不限於)下列各項:

  1. 使用網域名稱或 IP 位址之權利:CA 於簽發憑證時:

    1. 建立程序,以驗證申請者(Applicant)對憑證 subject 欄位及 subjectAltName 擴充欄位所列之網域名稱(Domain Name)及 IP 位址(IP address)具有使用權或控管權(或僅就網域名稱而言,已由具有該網域名稱使用權或控管權之人授予該等權利或控管權);
    2. 於簽發憑證時遵從該程序;及
    3. 於 CA 之憑證政策(CP)及/或憑證實務作業基準(CPS)中準確描述該程序;
  2. 憑證簽發之授權:CA 於簽發憑證時:

    1. 建立程序,以驗證主體(Subject)已授權簽發該憑證,且申請者代表(Applicant Representative)已獲授權代表主體申請該憑證;
    2. 於簽發憑證時遵從該程序;及
    3. 於 CA 之憑證政策(CP)及/或憑證實務作業基準(CPS)中準確描述該程序;
  3. 資訊正確性:CA 於簽發憑證時:

    1. 建立程序,以驗證憑證所載全部資訊之正確性;
    2. 於簽發憑證時遵從該程序;及
    3. 於 CA 之憑證政策(CP)及/或憑證實務作業基準(CPS)中準確描述該程序;
  4. 申請者身分:若憑證中包含主體識別資訊(Subject Identity Information),CA:

    1. 建立程序,依第 3.2 節及第 7.1.2 節驗證申請者身分;
    2. 於簽發憑證時遵從該程序;及
    3. 於 CA 之憑證政策(CP)及/或憑證實務作業基準(CPS)中準確描述該程序;
  5. 用戶協議:若 CA 與用戶非屬關係企業(Affiliate),則用戶與 CA 均為符合本文件要求規定之合法有效及可執行用戶協議的當事方;若 CA 與用戶隸屬同一實體或互為關係企業,則由申請者代表確認使用條款;

  6. 狀態:CA 維護一個每週 7 天、每天 24 小時(24x7)均可公開存取之儲存庫(Repository),提供所有未到期憑證之最新狀態(有效或已廢止)資訊;及

  7. 廢止:CA 將基於本文件所定之任一事由廢止憑證。

The Root CA SHALL be responsible for the performance and warranties of the Subordinate CA, for the Subordinate CA’s compliance with these Requirements, and for all liabilities and indemnification obligations of the Subordinate CA under these Requirements, as if the Root CA were the Subordinate CA issuing the Certificates.

根憑證機構(Root CA)應(SHALL)對下屬憑證機構(Subordinate CA)之履行及擔保、下屬憑證機構對本文件要求規定之遵循,以及下屬憑證機構依本文件要求規定所負之一切責任及賠償義務負責,如同根憑證機構即為簽發該等憑證的下屬憑證機構。