9.6.3 已翻譯 對應原文版本:2.3.0

用戶之聲明與擔保

跳至原文

Subscriber representations and warranties

The CA SHALL require, as part of the Subscriber Agreement or Terms of Use, that the Applicant make the commitments and warranties in this section for the benefit of the CA and the Certificate Beneficiaries.

憑證機構(Certification Authority,CA)應(SHALL)要求申請者於用戶協議(Subscriber Agreement)或使用條款(Terms of Use)中,為了 CA 及憑證受益人之利益作出本節所定之承諾及擔保。

Prior to the issuance of a Certificate, the CA SHALL obtain, for the express benefit of the CA and the Certificate Beneficiaries, either:

  1. The Applicant’s agreement to the Subscriber Agreement with the CA, or
  2. The Applicant’s acknowledgement of the Terms of Use.

於簽發憑證之前,CA 應(SHALL)為了 CA 及憑證受益人之利益,取得下列任一項:

  1. 申請者對其與 CA 之間的用戶協議之同意;或
  2. 申請者對使用條款之確認。

The CA SHALL implement a process to ensure that each Subscriber Agreement or Terms of Use is legally enforceable against the Applicant. In either case, the Agreement MUST apply to the Certificate to be issued pursuant to the certificate request. The CA MAY use an electronic or “click-through” Agreement provided that the CA has determined that such agreements are legally enforceable. A separate Agreement MAY be used for each certificate request, or a single Agreement MAY be used to cover multiple future certificate requests and the resulting Certificates, so long as each Certificate that the CA issues to the Applicant is clearly covered by that Subscriber Agreement or Terms of Use.

CA 應(SHALL)建立程序,確保每份用戶協議或使用條款均可依法對申請者執行。無論採何種方式,該協議應(MUST)適用於依憑證申請所簽發之憑證。CA 得(MAY)使用電子協議或「點選同意」(click-through)協議,前提是 CA 須確認此類協議可依法執行。每次憑證申請得(MAY)個別使用一份協議,亦得(MAY)以單一協議涵蓋未來多次憑證申請及其所產生之憑證,但以 CA 向申請者簽發之每張憑證均明確受該用戶協議或使用條款涵蓋為限。

The Subscriber Agreement or Terms of Use MUST contain provisions imposing on the Applicant itself (or made by the Applicant on behalf of its principal or agent under a subcontractor or hosting service relationship) the following obligations and warranties:

  1. Accuracy of Information: An obligation and warranty to provide accurate and complete information at all times to the CA, both in the certificate request and as otherwise requested by the CA in connection with the issuance of the Certificate(s) to be supplied by the CA;

  2. Protection of Private Key: An obligation and warranty by the Applicant to take all reasonable measures to assure control of, keep confidential, and properly protect at all times the Private Key that corresponds to the Public Key to be included in the requested Certificate(s) (and any associated activation data or device, e.g. password or token);

  3. Acceptance of Certificate: An obligation and warranty that the Subscriber will review and verify the Certificate contents for accuracy;

  4. Use of Certificate: An obligation and warranty to install the Certificate only on servers that are accessible at the subjectAltName(s) listed in the Certificate, and to use the Certificate solely in compliance with all applicable laws and solely in accordance with the Subscriber Agreement or Terms of Use;

  5. Reporting and Revocation: An obligation and warranty to:

    1. promptly request revocation of the Certificate, and cease using it and its associated Private Key, if there is any actual or suspected misuse or compromise of the Subscriber’s Private Key associated with the Public Key included in the Certificate, and
    2. promptly request revocation of the Certificate, and cease using it, if any information in the Certificate is or becomes incorrect or inaccurate;
  6. Termination of Use of Certificate: An obligation and warranty to promptly cease all use of the Private Key corresponding to the Public Key included in the Certificate upon revocation of that Certificate for reasons of Key Compromise.

  7. Responsiveness: An obligation to respond to the CA’s instructions concerning Key Compromise or Certificate misuse within a specified time period.

  8. Acknowledgment and Acceptance: An acknowledgment and acceptance that the CA is entitled to revoke the certificate immediately if the Applicant were to violate the terms of the Subscriber Agreement or Terms of Use or if revocation is required by the CA’s CP, CPS, or these Baseline Requirements.

用戶協議或使用條款應(MUST)包含要求申請者本身負擔下列義務並作出下列擔保之條款(或基於申請者之分包商、主機代管服務關係,代表其本人或代理人作出下列義務承諾及擔保):

  1. 資訊正確性:負有義務並擔保,無論於憑證申請時,或 CA 就其提供的憑證之簽發過程另有要求時,均隨時向 CA 提供正確且完整之資訊;

  2. 私密金鑰之保護:申請者負有義務並擔保其將採取一切合理措施,確保隨時控管、保密並妥善保護其所申請憑證中擬包含的公開金鑰(Public Key)之相對應私密金鑰(Private Key),以及任何相關的啟動資料或裝置(例如密碼或 Token);

  3. 憑證之接受:用戶負有義務並擔保其將確認及驗證憑證內容之正確性;

  4. 憑證之使用:負有義務並擔保,僅將憑證安裝於可透過憑證所列 subjectAltName 存取之伺服器,且僅於遵循所有適用法律與用戶協議或使用條款之情形下使用憑證;

  5. 通報及廢止:負有義務並擔保:

    1. 若與憑證所載之公開金鑰相對應的用戶私密金鑰發生任何實際或疑似遭誤用或遭破解,儘速請求廢止該憑證,並停止使用該憑證及相關私密金鑰;及
    2. 若憑證中任何資訊已經或即將變得不正確或不準確,儘速請求廢止該憑證,並停止使用該憑證;
  6. 停止使用憑證:負有義務並擔保,憑證因金鑰遭破解(Key Compromise)而廢止時,應儘速停止使用該憑證所載之公開金鑰相對應的私密金鑰;

  7. 回應:負有義務在指定期限內,回應 CA 就金鑰遭破解或憑證遭誤用的相關指示;

  8. 確認及接受:確認並接受,若申請者違反用戶協議或使用條款之約定,或 CA 的憑證政策(CP)、憑證實務作業基準(CPS)或本《基本要求》之規定須廢止憑證,CA 有權立即廢止該憑證。