2.1. 新增 Section 1.1 - RFC 4210 之后的变更
2.1. 新增 Section 1.1 - RFC 4210 之后的变更
以下小节描述对 [RFC4210] 的功能更新. 这些更新始终与基础规范相关. 因此, 只要可能, 都引用 [RFC4210] 中的原始章节.
在 [RFC4210] 当前 Section 1 之后插入本节:
1.1. RFC 4210 之后的变更
本文档进行了以下更新:
-
为各类 CMP server type 添加新的 extended key usage, 例如 registration authority 和 certification authority, 用于表达如下授权: 包含相应 extended key usage extension 的 certificate 所标识的 entity, 被授权作为所指示的 PKI management entity 行动.
-
扩展 multiple protection 的描述, 以覆盖更多使用场景, 例如 message 的 batch processing.
-
在 EncryptedValue 之外提供 EnvelopedData 作为首选选择, 以便更好地支持 CMP 中的 crypto agility. 注意, 根据
[RFC4211]Section 2.1 第 9 点, EncryptedValue 结构的使用已经被弃用, 转而使用 EnvelopedData 结构.[RFC4211]为 EncryptedKey 结构提供 EncryptedValue 和 EnvelopedData 两种选择, 以迁移到 EnvelopedData. 出于完整性和一致性考虑,[RFC4210]中所有出现的 EncryptedValue 类型都已被替换. 这包括对集中生成的 private key 的保护, certificate 的 encryption, 以及 revocation passphrase 的保护. 为了正确区分对 EnvelopedData 而非 EncryptedValue 的支持, 当 transaction 预期使用 EnvelopedData 时, 引入 CMP version 3. -
在 CertStatus 中提供可选的 hashAlg 字段, 以支持确认使用 signature algorithm 签名的 certificate, 例如为即将出现的 post-quantum algorithm 做准备, 这些算法不会直接指示用于计算 certHash 的具体 hash algorithm.
-
添加新的 general message type, 用于请求 CA certificate, root CA update, certificate request template 或 Certificate Revocation List (CRL) update.
-
将 polling 的用法扩展到 p10cr, certConf, rr, genm 和 error message.
-
删除
[RFC4210]Appendix D.2 中的 mandatory algorithm profile, 并改为引用 CMP Algorithms[RFC9481]的 Section 7.