gpt4 book ai didi

java - 如果使用jdk7,是否必须在证书中包含keyusage

转载 作者:太空宇宙 更新时间:2023-11-04 07:45:26 25 4
gpt4 key购买 nike

我使用的是jdk1.7。我正在使用自签名证书进行 SSL 握手。如果我使用 jdk1.7,是否必须在证书中包含 keyusage。请让我知道我很困惑。

谢谢,拉胡尔

最佳答案

这就是 RFC 5280说:

Conforming CAs MUST include this extension in certificates that
contain public keys that are used to validate digital signatures on
other public key certificates or CRLs. When present, conforming CAs
SHOULD mark this extension as critical.

但是,RFC 6818 ,这是 RFC 5280 的更新,内容如下:

Consistent with Section 3.4.61 of X.509 (11/2008) [X.509], we notethat use of self-issued certificates and self-signed certificatesissued by entities other than CAs are outside the scope of thisspecification. Thus, for example, a web server or client mightgenerate a self-signed certificate to identify itself. Thesecertificates and how a relying party uses them to authenticateasserted identities are both outside the scope of RFC 5280.

因此,如果您以 CA 的身份行事,则应包括 key 使用情况。无论如何,包含它可能是一个好主意,尽管根据上面的段落并没有严格要求它。

关于java - 如果使用jdk7,是否必须在证书中包含keyusage,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/15353595/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com