RFC 5280: 互联网 X.509 公钥基础设施证书和证书吊销列表 (CRL) 配置文件
Abstract
互联网 X.509 公钥基础设施 (Public Key Infrastructure, PKI) 标准族规定了用于在互联网上建立可信通信的证书, 证书吊销列表 (CRL) 和证书路径验证算法.
本备忘录为互联网 PKI 中证书和 CRL 的格式与语义规定了配置文件 (profile).本文描述了在互联网环境中处理认证路径 (certification path) 的过程.最后, 附录为所有已定义或引用的数据结构提供 ASN.1 模块.
本备忘录废止 RFC 3280.
Table of Contents
- 1. Introduction
- 2. Requirements and Assumptions
- 3. Overview of Approach
- 4. Certificate and Certificate Extensions Profile
- 5. CRL and CRL Extensions Profile
- 6. Certification Path Validation
- 7. Processing Rules for Internationalized Names
- 8. Security Considerations
- 9. IANA, 10. Acknowledgments, 11. References
- Appendix A. Pseudo-ASN.1 Structures and OIDs
- Appendix B. ASN.1 Notes
- Appendix C. Examples
Related RFCs and Resources
- 原始 RFC: RFC 5280
- 被废止的规范: RFC 3280
- 算法与编码: RFC 3279, RFC 4055, RFC 4491
- 国际化支持: RFC 3490, RFC 3987, RFC 4518
Key Concepts
Certificate (证书)
一种由认证机构 (Certification Authority, CA) 签发的数字凭证, 将公钥绑定到主体的身份.本规范为 X.509 version 3 证书规定配置文件.
Certificate Revocation List (证书吊销列表, CRL)
由 CA 签发的, 列出已被吊销但尚未过期的证书的列表.本规范为 X.509 version 2 CRL 规定配置文件.
Certification Path (认证路径)
从被依赖方 (relying party) 所信任的锚点 (trust anchor) 到目标证书之间的一系列证书, 需要通过路径验证算法进行验证.
Extension (扩展)
X.509 v3 证书和 v2 CRL 中可选的附加字段, 用于携带额外的约束, 策略或信息.
Critical vs Non-Critical (关键与非关键)
扩展可标记为 critical 或 non-critical.实现 MUST 理解和处理标记为 critical 的扩展; 若无法识别 critical 扩展, 则 MUST 拒绝该证书或 CRL.无法识别的 non-critical 扩展可安全忽略.
Updated by
本规范后续被以下文档更新: RFC 6818, RFC 8398, RFC 8399.