📄 pkix.htm
字号:
<HTML><HEAD><TITLE>Internet X.509 Public Key Infrastructure (PKIX)</TITLE><METANAME="GENERATOR"CONTENT="Modular DocBook HTML Stylesheet Version 1.55"><LINKREL="HOME"TITLE="The Open–source PKI Book"HREF="ospki-book.htm"><LINKREL="PREVIOUS"TITLE="The NIST Public Key Infrastructure Program"HREF="fpki.htm"><LINKREL="NEXT"TITLE="Concepts"HREF="pkix-concepts.htm"></HEAD><BODYCLASS="CHAPTER"BGCOLOR="#FFFFFF"TEXT="#000000"LINK="#0000FF"VLINK="#840084"ALINK="#0000FF"><DIVCLASS="NAVHEADER"><TABLEWIDTH="100%"BORDER="0"CELLPADDING="0"CELLSPACING="0"><TR><THCOLSPAN="3"ALIGN="center">The Open–source PKI Book: A guide to PKIs and Open–source Implementations</TH></TR><TR><TDWIDTH="10%"ALIGN="left"VALIGN="bottom"><AHREF="fpki.htm">Prev</A></TD><TDWIDTH="80%"ALIGN="center"VALIGN="bottom"></TD><TDWIDTH="10%"ALIGN="right"VALIGN="bottom"><AHREF="pkix-concepts.htm">Next</A></TD></TR></TABLE><HRALIGN="LEFT"WIDTH="100%"></DIV><DIVCLASS="CHAPTER"><H1><ANAME="PKIX">Chapter 6. Internet X.509 Public Key Infrastructure (PKIX)</A></H1><DIVCLASS="TOC"><DL><DT><B>Table of Contents</B></DT><DT><AHREF="pkix.htm#PKIX-ABBREVIATIONS">Abbreviations</A></DT><DT><AHREF="pkix-concepts.htm">Concepts</A></DT><DT><AHREF="pkix-overview.htm">Overview of the PKIX approach</A></DT></DL></DIV><P> In this chapter, we shall provide an informal introduction to the <SPANCLASS="ACRONYM">PKIX</SPAN> Internet Standards which are being developed by the <AHREF="http://www.ietf.org/html.charters/pkix-charter.html"TARGET="_top"> <SPANCLASS="ACRONYM">PKIX</SPAN> Working Group</A>. </P><DIVCLASS="SECT1"><H1CLASS="SECT1"><ANAME="PKIX-ABBREVIATIONS">Abbreviations</A></H1><P> To avoid confusion regarding the PKIX terminology, we include the list of terms as they are found in the PKIX document <TTCLASS="FILENAME">draft-ietf-pkix-roadmap-05</TT>. Their full explanation can be found at the Glossary. <DIVCLASS="TABLE"><P><B>Table 6-1. PKIX Terms</B></P><TABLEBORDER="1"CLASS="CALSTABLE"><THEAD><TR><THALIGN="LEFT"VALIGN="TOP">Term</TH><THALIGN="LEFT"VALIGN="TOP">Abbreviation</TH></TR></THEAD><TBODY><TR><TDALIGN="LEFT"VALIGN="TOP">Attribute Authority</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">AA</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Attribute Certificate</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">AC</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Certificate</TD><TDALIGN="LEFT"VALIGN="TOP"> </TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Certification Authority</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">CA</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Certificate Policy</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">CP</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Certification Practice Statement</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">CPS</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">End–Entity</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">EE</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Public Key Certificate</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">PKC</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Public Key Infrastructure</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">PKI</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Privilege Management Infrastructure</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">PMI</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Registration Authority</TD><TDALIGN="LEFT"VALIGN="TOP"><SPANCLASS="ACRONYM">RA</SPAN></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Relying Party</TD><TDALIGN="LEFT"VALIGN="TOP"> </TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Root CA</TD><TDALIGN="LEFT"VALIGN="TOP"> </TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Subordinate CA</TD><TDALIGN="LEFT"VALIGN="TOP"> </TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Subject</TD><TDALIGN="LEFT"VALIGN="TOP"> </TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Top CA</TD><TDALIGN="LEFT"VALIGN="TOP"> </TD></TR></TBODY></TABLE></DIV></P><P> With regard to the term <SPANCLASS="ACRONYM">X.509</SPAN>, it comes from the <SPANCLASS="ACRONYM">X.500</SPAN> specification on directory services. The directory services serve as a kind of electronic phonebook, where enabled applications can lookup included entities. Each entity has a identifying record or Certificate and the format of that Certificate follows the recommendation X.509 of the International Telecommunication Union (<SPANCLASS="ACRONYM">ITU</SPAN>). </P><P> X.500 itself is considered as too difficult to catch on, however, the X.509 format for certificates is used by succesive standards. For more information on X.500, one can read the online book entitiled <AHREF="http://www.salford.ac.uk/its024/X500.htm"TARGET="_top"> Understanding X.500 – The Directory</A> by D.W.Chadwick. </P></DIV></DIV><DIVCLASS="NAVFOOTER"><HRALIGN="LEFT"WIDTH="100%"><TABLEWIDTH="100%"BORDER="0"CELLPADDING="0"CELLSPACING="0"><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top"><AHREF="fpki.htm">Prev</A></TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"><AHREF="ospki-book.htm">Home</A></TD><TDWIDTH="33%"ALIGN="right"VALIGN="top"><AHREF="pkix-concepts.htm">Next</A></TD></TR><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top">The NIST Public Key Infrastructure Program</TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"> </TD><TDWIDTH="33%"ALIGN="right"VALIGN="top">Concepts</TD></TR></TABLE></DIV></BODY></HTML>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -