跳到主要内容

2.1. 新增 Section 1.1 - RFC 4210 之后的变更

2.1. 新增 Section 1.1 - RFC 4210 之后的变更

以下小节描述对 [RFC4210] 的功能更新. 这些更新始终与基础规范相关. 因此, 只要可能, 都引用 [RFC4210] 中的原始章节.

[RFC4210] 当前 Section 1 之后插入本节:

1.1. RFC 4210 之后的变更

本文档进行了以下更新:

  • 为各类 CMP server type 添加新的 extended key usage, 例如 registration authority 和 certification authority, 用于表达如下授权: 包含相应 extended key usage extension 的 certificate 所标识的 entity, 被授权作为所指示的 PKI management entity 行动.

  • 扩展 multiple protection 的描述, 以覆盖更多使用场景, 例如 message 的 batch processing.

  • 在 EncryptedValue 之外提供 EnvelopedData 作为首选选择, 以便更好地支持 CMP 中的 crypto agility. 注意, 根据 [RFC4211] Section 2.1 第 9 点, EncryptedValue 结构的使用已经被弃用, 转而使用 EnvelopedData 结构. [RFC4211] 为 EncryptedKey 结构提供 EncryptedValue 和 EnvelopedData 两种选择, 以迁移到 EnvelopedData. 出于完整性和一致性考虑, [RFC4210] 中所有出现的 EncryptedValue 类型都已被替换. 这包括对集中生成的 private key 的保护, certificate 的 encryption, 以及 revocation passphrase 的保护. 为了正确区分对 EnvelopedData 而非 EncryptedValue 的支持, 当 transaction 预期使用 EnvelopedData 时, 引入 CMP version 3.

  • 在 CertStatus 中提供可选的 hashAlg 字段, 以支持确认使用 signature algorithm 签名的 certificate, 例如为即将出现的 post-quantum algorithm 做准备, 这些算法不会直接指示用于计算 certHash 的具体 hash algorithm.

  • 添加新的 general message type, 用于请求 CA certificate, root CA update, certificate request template 或 Certificate Revocation List (CRL) update.

  • 将 polling 的用法扩展到 p10cr, certConf, rr, genm 和 error message.

  • 删除 [RFC4210] Appendix D.2 中的 mandatory algorithm profile, 并改为引用 CMP Algorithms [RFC9481] 的 Section 7.