跳到主要内容

2.4. 新增 Section 5.1.1.3 - CertProfile

2.4. 新增 Section 5.1.1.3 - CertProfile

[RFC4210] Section 5.1.1 定义 PKIHeader 以及 generalInfo 字段中使用的 id-it OID. 本节引入 id-it-certProfile.

[RFC4210] Section 5.1.1.2 之后插入本节:

5.1.1.3. CertProfile

EE 使用该项来指示特定 certificate profile, 例如在请求新 certificate 或 certificate request template 时; 参见 Section 5.3.19.16.

id-it-certProfile  OBJECT IDENTIFIER ::= {id-it 21}
CertProfileValue ::= SEQUENCE SIZE (1..MAX) OF UTF8String

当用于 ir/cr/kur/genm 时, 该值包含的元素数量 MUST NOT 多于 CertReqMsg 或 InfoTypeAndValue 元素数量, 并且 certificate profile name 按给定顺序引用这些元素.

当用于 p10cr 时, 该值 MUST NOT 包含多个 certificate profile name.