我问了另一个关于证书策略映射的问题。这是一个不同的问题。这是关于证书策略的。
引用 X.509 RFC:
In an end entity certificate, these policy information terms indicate
the policy under which the certificate has been issued and the
purposes for which the certificate may be used. In a CA certificate,
these policy information terms limit the set of policies for
certification paths that include this certificate. When a CA does
not wish to limit the set of policies for certification paths that
include this certificate, it MAY assert the special policy anyPolicy,
with a value of { 2 5 29 32 0 }.
假设我们有以下 X.509 证书链:
root CA ---> intermediary CA ---> client cert
听起来链中每个孩子拥有的一组策略将始终是父策略的子集?那是对的吗?