ETSI TS 119 412-2-2015 Electronic Signatures and Infrastructures (ESI) Certificate Profiles Part 2 Certificate profile for certificates issued to natural persons (V2 0 16)《电子签名和基础设_1.pdf

上传人:unhappyhay135 文档编号:740331 上传时间:2019-01-11 格式:PDF 页数:12 大小:90.56KB
下载 相关 举报
ETSI TS 119 412-2-2015 Electronic Signatures and Infrastructures (ESI) Certificate Profiles Part 2 Certificate profile for certificates issued to natural persons (V2 0 16)《电子签名和基础设_1.pdf_第1页
第1页 / 共12页
ETSI TS 119 412-2-2015 Electronic Signatures and Infrastructures (ESI) Certificate Profiles Part 2 Certificate profile for certificates issued to natural persons (V2 0 16)《电子签名和基础设_1.pdf_第2页
第2页 / 共12页
ETSI TS 119 412-2-2015 Electronic Signatures and Infrastructures (ESI) Certificate Profiles Part 2 Certificate profile for certificates issued to natural persons (V2 0 16)《电子签名和基础设_1.pdf_第3页
第3页 / 共12页
ETSI TS 119 412-2-2015 Electronic Signatures and Infrastructures (ESI) Certificate Profiles Part 2 Certificate profile for certificates issued to natural persons (V2 0 16)《电子签名和基础设_1.pdf_第4页
第4页 / 共12页
ETSI TS 119 412-2-2015 Electronic Signatures and Infrastructures (ESI) Certificate Profiles Part 2 Certificate profile for certificates issued to natural persons (V2 0 16)《电子签名和基础设_1.pdf_第5页
第5页 / 共12页
点击查看更多>>
资源描述

1、 ETSI TS 119 412-2 V2.0.16 (2015-07) Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 2: Certificate profile for certificates issued to natural persons TECHNICAL SPECIFICATION ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)2Reference RTS/ESI-0019412-2-TS Keywords electronic signa

2、ture, IP, profile, security, trust services ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The

3、 present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization o

4、f ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware t

5、hat the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: https:

6、/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be m

7、odified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2015. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benef

8、it of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)3Contents Intellectual Property Right

9、s 4g3Foreword . 4g3Modal verbs terminology 4g3Introduction 4g31 Scope 5g32 References 5g32.1 Normative references . 5g32.2 Informative references 6g33 Definitions and abbreviations . 6g33.1 Definitions 6g33.2 Abbreviations . 6g34 Void 7g35 General certificate profile requirements . 7g35.1 Generic re

10、quirements . 7g35.2 Basic certificate fields 7g35.2.1 Version 7g35.2.2 Void 7g35.2.3 Signature . 7g35.2.4 Issuer . 7g35.2.4.1 Legal person issuers 7g35.2.4.2 Natural person issuers . 8g35.2.5 Void 8g35.2.6 Subject 8g35.2.7 Subject public key info . 8g35.3 Void 9g35.4 Standard certificate extensions

11、. 9g35.4.1 Authority key identifier 9g35.4.2 Void 9g35.4.3 Key usage 9g35.4.4 Void 10g35.4.5 Certificate policies 10g35.4.6 Policy mappings 10g35.4.7 Subject alternative name . 10g35.4.8 Issuer alternative name . 10g35.4.9 Subject directory attributes . 10g35.4.10 Void 10g35.4.11 Name constraints 10

12、g35.4.12 Policy constraints 10g35.4.13 Extended key usage 10g35.4.14 CRL distribution points 10g35.4.15 Inhibit any-policy 10g35.4.16 Void 11g35.5 IETF RFC 5280 internet certificate extensions 11g35.5.1 Authority Information Access. 11g35.5.2 Void 11g35.6 Void 11g35.6.1 Void 11g35.6.2 Void 11g36 EU

13、qualified certificate requirements . 11g36.1 EU QCStatements. 11g36.2 Certificate policies 11g3History 12 ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)4Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining t

14、o these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. L

15、atest updates are available on the ETSI Web server (http:/ipr.etsi.org). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI

16、Web server) which are, or may be, or may become, essential to the present document. Foreword This Technical Specification (TS) has been produced by ETSI Technical Committee Electronic Signatures and Infrastructures (ESI). The present document is part 2 of the multipart deliverable covering the Certi

17、ficates Profiles. Full details of the entire series can be found in part 1 i.4. The present document was previously published as ETSI TS 102 280. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not“, “may“, “need not“, “will“, “will not“, “can“ and “cannot“ ar

18、e to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. Introduction ITU and ISO issued standards for certification of public keys in ITU

19、 X.509 | ISO/IEC 9594-8 i.3 which are used for the security of communications and data for a wide range of electronic applications. Regulation (EU) No 910/2014 i.5 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transaction

20、s in the internal market and repealing Directive 1999/93/EC defines requirements on specific types of certificates named “qualified certificates“. Implementation of Directive 1999/93/EC i.1 and deployment of certificate infrastructures throughout Europe as well as in countries outside of Europe, hav

21、e resulted in a variety of certificate implementations for use in public and closed environments, where some are declared as qualified certificates while others are not. Applications need support from standardized identity certificates profiles, in particular when applications are used for electroni

22、c signatures, authentication and secure electronic exchange in open environments and international trust scenarios, but also when certificates are used in local application contexts. This multi-part document aims to maximize the interoperability of systems issuing and using certificates both in the

23、European context under the Regulation (EU) No 910/2014 i.5 and in the wider international environment. ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)51 Scope The present document specifies requirements on the content of certificates issued to natural persons. This profile builds on IETF RFC 5280 1 for gen

24、eric profiling of Recommendation ITU-T X.509 / ISO/IEC 9594-8 i.3. This profile supports the requirements of EU qualified certificates as specified in the Regulation (EU) No 910/2014 i.5 as well as other forms of certificate. The scope of the present document is primary limited to facilitate interop

25、erable processing and display of certificate information. This profile therefore excludes support for some certificate information content options, which can be perfectly valid in a local context but which are not regarded as relevant or suitable for use in widely deployed applications. The present

26、document focuses on requirements on certificate content. Requirements on decoding and processing rules are limited to aspects required to process certificate content defined in the present document. Further processing requirements are only specified for cases where it adds information that is necess

27、ary for the sake of interoperability. Certain applications or protocols impose specific requirements on certificate content. The present document is based on the assumption that these requirements are adequately defined by the respective application or protocol. It is therefore outside the scope of

28、the present document to specify such application or protocol specific certificate content. 2 References 2.1 Normative references References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version

29、 applies. For non-specific references, the latest version of the referenced document (including any amendments) applies. Referenced documents which are not found to be publicly available in the expected location might be found at http:/docbox.etsi.org/Reference. NOTE: While any hyperlinks included i

30、n this clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are necessary for the application of the present document. 1 IETF RFC 5280: “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (C

31、RL) Profile“. 2 ETSI TS 119 412-5: “Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 5: QCStatements“. 3 ETSI TS 119 312: “Electronic Signatures and Infrastructures (ESI); Cryptographic Suites“. 4 IETF RFC 2616: “Hypertext Transfer Protocol - HTTP/1.1“. 5 IETF RFC 2255: “T

32、he LDAP URL Format“. 6 IETF RFC 2818: “HTTP Over TLS“. 7 Recommendation ITU-T X.520 (10/2012): “Information technology - Open Systems Interconnection - The Directory: Selected attribute types“. ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)62.2 Informative references References are either specific (identi

33、fied by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies. NOTE: While any hyperlinks included in this cl

34、ause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are not necessary for the application of the present document but they assist the user with regard to a particular subject area. i.1 Directive 1999/93/EC of the European Par

35、liament and of the Council of 13 December 1999 on a Community framework for electronic signatures. i.2 IETF RFC 6960: “X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP“. i.3 Recommendation ITU-T X.509/ISO/IEC 9594-8: “Information technology - Open Systems Interconne

36、ction - The Directory: Public-key and attribute certificate frameworks“. i.4 ETSI TS 119 412-1: “Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 1: Overview and common data structures“. i.5 Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 Ju

37、ly 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. i.6 ETSI TS 119 411-1: “Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; P

38、art 1: General Requirements“. i.7 ETSI TS 119 411-2: “Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; Part 2: Requirements for trust service providers issuing EU qualified certificates“. 3 Definitions and abbreviatio

39、ns 3.1 Definitions For the purposes of the present document, the terms and definitions given in ETSI TS 119 412-1 i.4 apply. 3.2 Abbreviations For the purposes of the present document, the following abbreviations apply: CA Certification Authority CRL Certificate Revocation ListEC European Commission

40、 EU European Union ISO International Standards Organization OCSP Online Certificate Status Protocol OID Object Identifier RFC Request For Comments RSA Algorithm invented by Rivest, Adleman and Shamir SHA Secure Hash Algorithm URI Uniform Resource Identifier ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)74

41、 Void 5 General certificate profile requirements 5.1 Generic requirements All certificate fields and extensions shall comply with IETF RFC 5280 1 with the amendments specified in the present document. Certificate extensions shall not be marked critical unless criticality is explicitly allowed or req

42、uired in the present document or in IETF RFC 5280 1. 5.2 Basic certificate fields 5.2.1 Version The version shall be V3 (defined by the integer value 2). 5.2.2 Void 5.2.3 Signature Signature algorithm shall be selected according to ETSI TS 119 312 3. 5.2.4 Issuer 5.2.4.1 Legal person issuers The ide

43、ntity of the issuer, when the issuer is a legal person, shall contain at least the following attributes as specified in Recommendation ITU-T X.520 7: countryName; organizationName; organizationIdentifier; and commonName. Additional attributes may be present. The countryName attribute shall specify t

44、he country in which the issuer of the certificate is established. The organizationName attribute shall contain the full registered name of the certificate issuing organization. The organizationIdentifier attribute shall contain an identification of the certificate issuing organization different from

45、 the organization name. Certificates may include one or more semantics identifiers as specified in clause 5 of ETSI TS 119 412-1 i.4. The commonName attribute value shall contain a name commonly used by the subject to represent itself. This name need not be an exact match of the fully registered org

46、anization name. NOTE: Earlier editions of X.520 had size limitations on attribute content where e.g. commonName used to have a size limitation of 64 characters. The size limitations of attributes referenced in the present document (except countryName) are no longer present in the current edition of

47、X.520. Interoperability issues can arise due to current implementations of X.520 still operating in accordance with the previous size limitations. ETSI ETSI TS 119 412-2 V2.0.16 (2015-07)85.2.4.2 Natural person issuers The identity of the issuer, when the issuer is a natural person shall contain at

48、least the following attributes as specified in Recommendation ITU-T X.520 7: countryName; choice of (givenName and surname) or pseudonym; serialNumber; and commonName. Additional attributes may be present. The countryName attribute shall specify a country that is consistent with the legal jurisdicti

49、on under which certificates are issued. Other attributes listed above shall comply with requirements stated in clause 5.2.6. 5.2.5 Void 5.2.6 Subject The subject field shall include the following attributes as specified in Recommendation ITU-T X.520 7: countryName; choice of (givenName and surname) or pseudonym; and commonName. If these mandatory attributes are not sufficient to ensure Subject name uniqueness within the context of the issuer, then the serialNumber shall be present. The subject f

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 标准规范 > 国际标准 > 其他

copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1