2.26. 更新 Appendix B - Revocation Passphrase 的使用
2.26. 更新 Appendix B - Revocation Passphrase 的使用
[RFC4210] Appendix B 描述 revocation passphrase 的使用. 由于本文档按上文 Section 2.7 所述, 将 [RFC4210] 更新为使用 parent structure EncryptedKey 而不是 EncryptedValue, 因此相应更新该描述.
将本节的第一个 bullet point 替换为以下文本:
- Section 5.3.19.9 中指定的 OID 和 value MAY 随时在 GenMsg message 中发送, 或 MAY 随时在任何 PKIMessage 的 PKIHeader 的 generalInfo 字段中发送. (特别是, Section 5.2.2 中描述的 EncryptedKey 结构可以在 certConf message 的 header 中发送, 该 certConf message 用于确认接受 initialization request 或 certificate request message 中请求的 certificate.) 这会把 entity 选择的 revocation passphrase 传达给相关 CA/RA. 使用 EnvelopedData 时, 它位于 encryptedContent 字段的 decrypted bytes 中. 使用 EncryptedValue 时, 它位于 encValue 字段的 decrypted bytes 中. 此外, 该传输以适当的 confidentiality characteristic 完成.
将本节的第三个 bullet point 替换为以下文本:
[RFC2985]中规定的 EnvelopedData 的 localKeyId attribute, 或 EncryptedValue 的 valueHint 字段, MAY 包含 key identifier (由该 entity 连同 passphrase 本身一起选择), 以帮助后续检索正确的 passphrase (例如, 当 revocation request 由该 entity 构造并由 CA/RA 接收时).