**JPRSサーバー証明書** **認証局証明書ポリシー/認証局運用規程** **(Certificate Policy/Certification Practice Statement)** **Version 2.12** 2026年8月4日 株式会社日本レジストリサービス
| 改版履歴 | ||
|---|---|---|
| 版数 | 日付 | 内容 |
| 1.00 | 2019.06.17 | 初版発行 |
| 1.10 | 2020.04.01 | Mozilla Root Store Policy(v2.7)への準拠に伴う改訂 |
| 1.11 | 2021.04.01 | 表紙の日付及びVersionを更新 |
| 1.12 | 2022.04.01 | 表紙の日付及びVersionを更新 |
| 1.20 | 2022.09.30 | 「6.3.2 私有鍵および公開鍵の有効期間」のタイトル変更および現状に合わせて記述を追加・修正 |
| 1.30 | 2023.06.08 | Baseline Requirementsへの準拠に関する記述の修正 |
| 1.40 | 2023.08.28 | Baseline Requirementsの各要件への準拠を明確にするた め記述見直し |
| 1.50 | 2024.02.22 | Baseline Requirementsの正式名称に関する記述の修正 |
| 1.51 | 2024.06.05 | 「1.6 定義と略語」の修正 |
| 1.52 | 2024.08.26 | 「5.4 監査ログの手続」の修正 |
| 1.53 | 2024.11.07 | 「6.1.1 鍵ペアの生成」、「8.4 監査で扱われる事項」を更新 |
| 1.54 | 2025.05.20 | 「5.4.1 記録されるイベントの種類」、「8.7 内部監査」を更新 |
| 2.00 | 2025.08.22 | CPS Version 1.54とCP Version 3.80を統合し、本CP/CPS Version 2.00として改訂 Baseline Requirementsの各要件への準拠を明確にするた め記述見直し |
| 2.10 | 2025.11.28 | 「1.6 定義と略語」、「3.2.2.4 ドメイン名の認証」、「3.2.2.8 CAAレコード」、「4.2.1 本人性確認と認証の実施」、「5.7.1 事故および危殆化時の手続」、「6.3.2 証明書の有効期間と私有鍵および公開鍵の有効期間」、「6.7 ネットワークセキュリティ管理」、「8.6 監査結果の開示」を更新 |
| 2.11 | 2026.03.31 | 「1.1 概要」、「1.6 定義と略語」、「3.2.2.4 ドメイン名の認証」、「4.2.2 証明書申請の承認または却下」を更新 |
| 2.12 | 2026.08.04 | 「1.6 定義と略語」、「3.2.2.4 ドメイン名の認証」、「4.2.1 本人性確認と認証の実施」、「4.9.1 証明書失効事由」「5.4.1 記録されるイベントの種類」、「5.4.3 監査ログを保持する期間」、「6.1.1 鍵ペアの生成」、「7.1.1 バージョン番号」、「7.2.1 バージョン番号」、「8.1 監査の頻度」「8.4 監査で扱われる事項」を更新 |
| 本CAが発行する証明書種類 | 準拠するべき規準 |
|---|---|
| TLSサーバー証明書 |
|
| 証明書発行日 | 最大データ再利用期間 | |
|---|---|---|
| 2026年3月15日より前 | 825日 | |
| 2026年3月15日以降 | 398日 | |
| 証明書発行日 | 最大データ再利用期間 | |
|---|---|---|
| 2026年3月15日より前 | 398日 | |
| 2026年3月15日以降 | 2027年3月15日より前 | 200日 |
| 2027年3月15日以降 | 2029年3月15日より前 | 100日 |
| 2029年3月15日以降 | 10日 | |
| 本CA | 本CAが発行する証明書 | |
|---|---|---|
| digitalSignature | ― | yes |
| nonRepudiation | ― | ― |
| keyEncipherment | ― | yes (ただし、ECDSA鍵を利用した証明書を除く) |
| dataEncipherment | ― | ― |
| keyAgreement | ― | ― |
| keyCertSign | yes | ― |
| cRLSign | yes | ― |
| encipherOnly | ― | ― |
| decipherOnly | ― | ― |
| 証明書の発行日 | 最大有効期間 | |
|---|---|---|
| 2026年3月15日より前 | 398日 | |
| 2026年3月15日以降 | 2027年3月15日より前 | 200日 |
| 2027年3月15日以降 | 2029年3月15日より前 | 100日 |
| 2029年3月15日以降 | 47日 | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CAが証明書に割り当てる整数のシリアル番号 | - | |
| Signature Algorithm | sha256 With RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O=Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN=JPRS Domain Validation Authority - G4 (2)組織認証型 CN=JPRS Organization Validation Authority - G4 |
- | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2009/3/1 00:00:00 GMT | - | |
| Subject | Country | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(国)として、「C=JP」を記載する |
- |
| State Or Province | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(都道府県名)(必須) |
- | |
| Locality | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(市区町村名)(必須) |
- | |
| Organization | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の名称(必須) |
- | |
| Organizational Unit | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の部署名(任意) (ただし、2021年11月18日以降に発行する証明書には記載しない) 本項目には「記号のみおよびスペースのみで構成される文字列」を指定してはならない 本項目には以下の文字列を含めてはならない 申請組織以外の情報と誤解される恐れのある名称・社名・商号・商標 法人格を示す文字列(「Co., Ltd」など) 特定の自然人を参照させる文字列 住所を示す文字列 電話番号 ドメイン名およびIPアドレス 「空欄」「該当なし」などの意味を示す文字列(「null」、「N/A」など) |
- | |
| Common Name | 証明書をインストールする予定のサーバーのDNS内で使われるホスト名(必須) 証明書のSubject Alt Name拡張領域に含まれるdNSnameの値の1つを文字単位のコピーとしてエンコードする |
- | |
| Subject Public Key Info | Subjectの公開鍵RSA 2048ビット | - | |
| 拡張領域 | 設定内容 | critical | |
| Key Usage | digitalSignature, keyEncipherment |
y | |
| Extended Key Usage | TLS Web Server Authentication | n | |
| Subject Alt Name | dNSName=サーバー名(複数の場合あり) | n | |
| Certificate Policies | [1] Certificate Policy 1.3.6.1.4.1.53827.1.1.4 CPS http://jprs.jp/pubcert/info/repository/ [2] Certificate Policy (1)ドメイン認証型 2.23.140.1.2.1 (2)組織認証型 2.23.140.1.2.2 |
n | |
| CRL Distribution Points | (1)ドメイン認証型 http://repo.pubcert.jprs.jp/sppca/jprs/dvca_g4/fullcrl.crl (2)組織認証型 http://repo.pubcert.jprs.jp/sppca/jprs/ovca_g4/fullcrl.crl |
n | |
| Authority Information Access | [1] ocsp(1.3.6.1.5.5.7.48.1) (1)ドメイン認証型 http://dv.g4.ocsp.pubcert.jprs.jp (2)組織認証型 http://ov.g4.ocsp.pubcert.jprs.jp [2] ca issuers(1.3.6.1.5.5.7.48.2) (1)ドメイン認証型 http://repo.pubcert.jprs.jp/sppca/jprs/dvca_g4/JPRS_DVCA_G4_DER.cer (2)組織認証型 http://repo.pubcert.jprs.jp/sppca/jprs/ovca_g4/JPRS_OVCA_G4_DER.cer |
n | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| Subject Key Identifier | Subject公開鍵のSHA-1ハッシュ値(160ビット) | n | |
Certificate Transparency Timestamp List (1.3.6.1.4.1.11129.2.4.2) |
エンコードされたSignedCertificateTimestampList を含むOCTET STRINGとする | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CAが証明書に割り当てる整数のシリアル番号 | - | |
| Signature Algorithm | sha256 With RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O=Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN= JPRS DV RSA CA 2024 G1 (2)組織認証型 CN= JPRS OV RSA CA 2024 G1 |
- | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2009/3/1 00:00:00 GMT | - | |
| Subject | Country | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(国)として、「C=JP」を記載する |
- |
| State Or Province | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(都道府県名)(必須) |
- | |
| Locality | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(市区町村名)(必須) |
- | |
| Organization | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の名称(必須) |
- | |
| Common Name | 証明書をインストールする予定のサーバーのDNS内で使われるホスト名(必須) 証明書のSubject Alt Name拡張領域に含まれるdNSnameの値の1つを文字単位のコピーとしてエンコードする |
- | |
| Subject Public Key Info | Subjectの公開鍵 RSA2048 ビット、 RSA3072 ビット、RSA4096 ビットの いずれか |
- | |
| 拡張領域 | 設定内容 | critical | |
| Key Usage | digitalSignature, keyEncipherment |
y | |
| Extended Key Usage | TLS Web Server Authentication、 TLS Web Client Authentication(任意) |
n | |
| Subject Alt Name | dNSName=サーバー名(複数の場合あり) | n | |
| Certificate Policies | Certificate Policy (1)ドメイン認証型 2.23.140.1.2.1 (2)組織認証型 2.23.140.1.2.2 |
n | |
| CRL Distribution Points | (1)ドメイン認証型 http://repo.pubcert.jprs.jp/sppca/jprs/dvca_rsa2024g1/fullcrl.crl (2)組織認証型 http://repo.pubcert.jprs.jp/sppca/jprs/ovca_rsa2024g1/fullcrl.crl |
n | |
| Authority Information Access | [1] ocsp(1.3.6.1.5.5.7.48.1) (1)ドメイン認証型 http://dv.rsa2024g1.ocsp.pubcert.jprs.jp (2)組織認証型 http://ov.rsa2024g1.ocsp.pubcert.jprs.jp [2] ca issuers(1.3.6.1.5.5.7.48.2) (1)ドメイン認証型 http://repo.pubcert.jprs.jp/sppca/jprs/dvca_rsa2024g1/JPRS_DVCA_RSA2024G1_DER.cer (2)組織認証型 http://repo.pubcert.jprs.jp/sppca/jprs/ovca_rsa2024g1/JPRS_OVCA_RSA2024G1_DER.cer |
n | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| Subject Key Identifier | Subject公開鍵のSHA-1ハッシュ値(160ビット) | n | |
Certificate Transparency Timestamp List (1.3.6.1.4.1.11129.2.4.2) |
エンコードされたSignedCertificateTimestampList を含むOCTET STRINGとする(任意) | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CAが証明書に割り当てる整数のシリアル番号 | - | |
| Signature Algorithm | ecdsa-with-SHA384 | - | |
| Issuer | Country | C=JP | - |
| Organization | O=Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN= JPRS DV ECC CA 2024 G1 (2)組織認証型 CN= JPRS OV ECC CA 2024 G1 |
- | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2009/3/1 00:00:00 GMT | - | |
| Subject | Country | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(国)として、「C=JP」を記載する |
- |
| State Or Province | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(都道府県名)(必須) |
- | |
| Locality | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の住所(市区町村名)(必須) |
- | |
| Organization | (1)ドメイン認証型 記載しない (2)組織認証型 証明書利用者の名称(必須) |
- | |
| Common Name | 証明書をインストールする予定のサーバーのDNS内で使われるホスト名(必須) 証明書のSubject Alt Name拡張領域に含まれるdNSnameの値の1つを文字単位のコピーとしてエンコードする |
- | |
| Subject Public Key Info | Subjectの公開鍵 RSA2048 ビット、 RSA3072 ビット、RSA4096 ビット、P-256、P-384のいずれか |
- | |
| 拡張領域 | 設定内容 | critical | |
| Key Usage | digitalSignature keyEncipherment(ECDSA鍵を利用した証明書には記載しない) |
y | |
| Extended Key Usage | TLS Web Server Authentication、 TLS Web Client Authentication(任意) |
n | |
| Subject Alt Name | dNSName=サーバー名(複数の場合あり) | n | |
| Certificate Policies | Certificate Policy (1)ドメイン認証型 2.23.140.1.2.1 (2)組織認証型 2.23.140.1.2.2 |
n | |
| CRL Distribution Points | (1)ドメイン認証型 http://repo.pubcert.jprs.jp/sppca/jprs/dvca_ecc2024g1/fullcrl.crl (2)組織認証型 http://repo.pubcert.jprs.jp/sppca/jprs/ovca_ecc2024g1/fullcrl.crl |
n | |
| Authority Information Access | [1] ocsp(1.3.6.1.5.5.7.48.1) (1)ドメイン認証型 http://dv.ecc2024g1.ocsp.pubcert.jprs.jp (2)組織認証型 http://ov.ecc2024g1.ocsp.pubcert.jprs.jp [2] ca issuers(1.3.6.1.5.5.7.48.2) (1)ドメイン認証型 http://repo.pubcert.jprs.jp/sppca/jprs/dvca_ecc2024g1/JPRSDVCA_ECC2024G1_DER.cer (2)組織認証型 http://repo.pubcert.jprs.jp/sppca/jprs/ovca_ecc2024g1/JPRS_OVCA_ECC2024G1_DER.cer |
n | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| Subject Key Identifier | Subject公開鍵のSHA-1ハッシュ値(160ビット) | n | |
Certificate Transparency Timestamp List (1.3.6.1.4.1.11129.2.4.2) |
エンコードされたSignedCertificateTimestampList を含むOCTET STRINGとする(任意) | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CAが証明書に割り当てる整数のシリアル番号 | - | |
| Signature Algorithm | sha256 With RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O=SECOM Trust Systems CO.,LTD. | - | |
| Common Name | OU=Security Communication RootCA2 | - | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2009/3/1 00:00:00 GMT | - | |
| Subject | Country | C=JP | - |
| Organization | O=Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)組織認証型 CN=JPRS Organization Validation Authority - G4 (2)ドメイン認証型 CN=JPRS Domain Validation Authority - G4 |
- | |
| Subject Public Key Info | Subjectの公開鍵 2048 ビット | - | |
| 拡張領域 | 設定内容 | critical | |
| Authority Key Identifier | Issuer公開鍵の SHA-1 ハッシュ値(160 ビット) | n | |
| Subject Key Identifier | Subject公開鍵の SHA-1 ハッシュ値(160 ビット) | n | |
| Key Usage | Certificate Signing Off-line CRL Signing CRL Signing (06) |
y | |
| Certificate Policies | Certificate Policy 1.2.392.200091.100.901.4 CPS http://repository.secomtrust.net/SC-Root2/ |
n | |
| Basic Constraints | Subject Type=CA Path Length Constraint=0 |
y | |
| Extended Key Usage | TLS Web Server Authentication | n | |
| CRL Distribution Points | http://repository.secomtrust.net/SC-Root2/SCRoot2CRL.crl | n | |
| Authority Information Access | [1] ocsp(1.3.6.1.5.5.7.48.1) http://scrootca2.ocsp.secomtrust.net [2] ca issuers(1.3.6.1.5.5.7.48.2) http://repository.secomtrust.net/SC-Root2/SCRoot2ca.cer |
n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CAが証明書に割り当てる整数のシリアル番号 | - | |
| Signature Algorithm | Sha384 With RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O=SECOM Trust Systems Co., Ltd. | - | |
| Common Name | CN=SECOM TLS RSA Root CA 2024 | - | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2009/3/1 00:00:00 GMT | - | |
| Subject | Country | C=JP | - |
| Organization | O=Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)組織認証型 CN= JPRS OV RSA CA 2024 G1 (2)ドメイン認証型 CN= JPRS DV RSA CA 2024 G1 |
- | |
| Subject Public Key Info | Subjectの公開鍵 4096 ビット | - | |
| 拡張領域 | 設定内容 | critical | |
| Authority Key Identifier | Issuer公開鍵の SHA-1 ハッシュ値(160 ビット) | n | |
| Subject Key Identifier | Subject公開鍵の SHA-1 ハッシュ値(160 ビット) | n | |
| Key Usage | Certificate Signing Off-line CRL Signing CRL Signing (06) |
y | |
| Certificate Policies | [1] Certificate Policy (1)ドメイン認証型 2.23.140.1.2.1 (2)組織認証型 2.23.140.1.2.2 [2] Certificate Policy 1.2.392.200091.100.901.11 |
n | |
| Basic Constraints | Subject Type=CA Path Length Constraint=0 |
y | |
| Extended Key Usage | TLS Web Server Authentication TLS Web Client Authentication |
n | |
| CRL Distribution Points | http://repo1.secomtrust.net/root/tlsrsa/tlsrsarootca2024.crl | n | |
| Authority Information Access | [1] ocsp(1.3.6.1.5.5.7.48.1) http://tlsrsarootca2024.ocsp.secom-cert.jp [2] ca issuers(1.3.6.1.5.5.7.48.2) http://repo2.secomtrust.net/root/tlsrsa/tlsrsarootca2024.cer |
n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CAが証明書に割り当てる整数のシリアル番号 | - | |
| Signature Algorithm | ecdsa-with-SHA384 | - | |
| Issuer | Country | C=JP | - |
| Organization | O=SECOM Trust Systems CO.,LTD. | - | |
| Common Name | CN=Security Communication ECC RootCA1 | - | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2009/3/1 00:00:00 GMT | - | |
| Subject | Country | C=JP | - |
| Organization | O=Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)組織認証型 CN= JPRS OV ECC CA 2024 G1 (2)ドメイン認証型 CN= JPRS DV ECC CA 2024 G1 |
- | |
| Subject Public Key Info | Subjectの公開鍵 384 ビット | - | |
| 拡張領域 | 設定内容 | critical | |
| Authority Key Identifier | Issuer公開鍵の SHA-1 ハッシュ値(160 ビット) | n | |
| Subject Key Identifier | Subject公開鍵の SHA-1 ハッシュ値(160 ビット) | n | |
| Key Usage | Certificate Signing Off-line CRL Signing CRL Signing (06) |
y | |
| Certificate Policies | [1] Certificate Policy (1)ドメイン認証型 2.23.140.1.2.1 (2)組織認証型 2.23.140.1.2.2 [2] Certificate Policy 1.2.392.200091.100.902.1 |
n | |
| Basic Constraints | Subject Type=CA Path Length Constraint=0 |
y | |
| Extended Key Usage | TLS Web Server Authentication TLS Web Client Authentication |
n | |
| CRL Distribution Points | http://repository.secomtrust.net/SC-ECC-Root1/SCECCRoot1CRL.crl | n | |
| Authority Information Access | [1] ocsp(1.3.6.1.5.5.7.48.1) http://sceccrootca1.ocsp.secomtrust.net [2] ca issuers(1.3.6.1.5.5.7.48.2) http://repository.secomtrust.net/SC-ECC-Root1/SCECCRoot1ca.cer |
n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | 利用者向け証明書の同項目とバイト単位で同一 | - | |
| Serial Number | 同上 | - | |
| Signature Algorithm | 同上 | - | |
| Issuer | Country | 同上 | - |
| Organization | 同上 | - | |
| Common Name | 同上 | - | |
| Validity | NotBefore | 同上 | - |
| NotAfter | 同上 | - | |
| Subject | Country | 同上 | - |
| State Or Province | 同上 | - | |
| Locality | 同上 | - | |
| Organization | 同上 | - | |
| Common Name | 同上 | - | |
| Subject Public Key Info | 同上 | - | |
| 拡張領域 | 設定内容 | critical | |
| Precertificate Poison | extnValue OCTET STRING
|
y | |
| Key Usage | 利用者向け証明書の同項目とバイト単位で同一 | y | |
| Extended Key Usage | 同上 | n | |
| Subject Alt Name | 同上 | n | |
| Certificate Policies | 同上 | n | |
| CRL Distribution Points | 同上 | n | |
| Authority Information Access | 同上 | n | |
| Authority Key Identifier | 同上 | n | |
| Subject Key Identifier | 同上 | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CSPRNG から出力される少なくとも 64 ビットを含む、ゼロ(0)より大きく 2^159より小さい非連続的な数値でなければならない | - | |
| Signature Algorithm | sha256 With RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O= Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN=JPRS Domain Validation Authority - G4 (2)組織認証型 CN=JPRS Organization Validation Authority - G4 |
- | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2008/3/5 00:00:00 GMT | - | |
| Subject | Country | C=JP(固定値) | - |
| Organization | Japan Registry Services Co., Ltd. (固定値) |
- | |
| Common Name | OCSPサーバー名(必須) | - | |
| Subject Public Key Info | Subjectの公開鍵RSA 2048ビット | - | |
| 拡張領域 | 設定内容 | critical | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| Subject Key Identifier | Subject公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| KeyUsage | digitalSignature | y | |
| ExtendedKeyUsage | OCSPSigning | n | |
| OCSP No Check | null | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CSPRNG から出力される少なくとも 64 ビットを含む、ゼロ(0)より大きく 2^159より小さい非連続的な数値でなければならない | - | |
| Signature Algorithm | sha256 With RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O= Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN= JPRS DV RSA CA 2024 G1 (2)組織認証型 CN= JPRS OV RSA CA 2024 G1 |
- | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2008/3/5 00:00:00 GMT | - | |
| Subject | Country | C=JP(固定値) | - |
| Organization | Japan Registry Services Co., Ltd. (固定値) |
- | |
| Common Name | OCSPサーバー名(必須) | - | |
| Subject Public Key Info | Subjectの公開鍵 RSA2048 ビット、 RSA3072 ビット、RSA4096 ビットの いずれか |
- | |
| 拡張領域 | 設定内容 | critical | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| Subject Key Identifier | Subject公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| KeyUsage | digitalSignature | y | |
| ExtendedKeyUsage | OCSPSigning | n | |
| OCSP No Check | null | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 3 | - | |
| Serial Number | CSPRNG から出力される少なくとも 64 ビットを含む、ゼロ(0)より大きく 2^159より小さい非連続的な数値でなければならない | ||
| Signature Algorithm | ecdsa-with-SHA384 | - | |
| Issuer | Country | C=JP | - |
| Organization | O= Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN= JPRS DV ECC CA 2024 G1 (2)組織認証型 CN= JPRS OV ECC CA 2024 G1 |
- | |
| Validity | NotBefore | 例) 2008/3/1 00:00:00 GMT | - |
| NotAfter | 例) 2008/3/5 00:00:00 GMT | - | |
| Subject | Country | C=JP(固定値) | - |
| Organization | Japan Registry Services Co., Ltd. (固定値) |
- | |
| Common Name | OCSPサーバー名(必須) | - | |
| Subject Public Key Info | Subjectの公開鍵 256 ビット、 384 ビットのいずれか |
- | |
| 拡張領域 | 設定内容 | critical | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| Subject Key Identifier | Subject公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| KeyUsage | digitalSignature | y | |
| ExtendedKeyUsage | OCSPSigning | n | |
| OCSP No Check | null | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 2 | - | |
| Signature Algorithm | SHA256 with RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O= Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN=JPRS Domain Validation Authority - G4 (2)組織認証型 CN=JPRS Organization Validation Authority - G4 |
- | |
| This Update | 例) 2008/3/1 00:00:00 GMT | - | |
| Next Update | 例) 2008/3/5 00:00:00 GMT | - | |
| Revoked Certificates | Serial Number | 例) 0123456789 | - |
| Revocation Date | 例) 2008/3/1 00:00:00 GMT | - | |
| Reason Code | 失効理由コード(※) | - | |
| 拡張領域 | 設定内容 | critical | |
| CRL Number | CRL番号 | n | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 2 | - | |
| Signature Algorithm | SHA384 with RSA Encryption | - | |
| Issuer | Country | C=JP | - |
| Organization | O= Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN= JPRS DV RSA CA 2024 G1 (2)組織認証型 CN= JPRS OV RSA CA 2024 G1 |
- | |
| This Update | 例) 2008/3/1 00:00:00 GMT | - | |
| Next Update | 例) 2008/3/5 00:00:00 GMT | - | |
| Revoked Certificates | Serial Number | 例) 0123456789 | - |
| Revocation Date | 例) 2008/3/1 00:00:00 GMT | - | |
| Reason Code | 失効理由コード(※) | - | |
| 拡張領域 | 設定内容 | critical | |
| CRL Number | CRL番号 | n | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| 基本領域 | 設定内容 | critical | |
|---|---|---|---|
| Version | Version 2 | - | |
| Signature Algorithm | ecdsa-with-SHA384 | - | |
| Issuer | Country | C=JP | - |
| Organization | O= Japan Registry Services Co., Ltd. | - | |
| Common Name | (1)ドメイン認証型 CN= JPRS DV ECC CA 2024 G1 (2)組織認証型 CN= JPRS OV ECC CA 2024 G1 |
- | |
| This Update | 例) 2008/3/1 00:00:00 GMT | - | |
| Next Update | 例) 2008/3/5 00:00:00 GMT | - | |
| Revoked Certificates | Serial Number | 例) 0123456789 | - |
| Revocation Date | 例) 2008/3/1 00:00:00 GMT | - | |
| Reason Code | 失効理由コード(※) | - | |
| 拡張領域 | 設定内容 | critical | |
| CRL Number | CRL番号 | n | |
| Authority Key Identifier | Issuer公開鍵のSHA-1ハッシュ値(160ビット) | n | |
| 失効理由コード | この失効理由コードを指定する事由 |
|---|---|
| #0 unspecified | 該当なし ・以下に定める失効事由のいずれにも該当しない場合 |
| #1 keyCompromise | 鍵の危殆化 ・証明書利用者の私有鍵が危殆化した、またはその可能性がある場合 |
| #3 affiliationChanged | 組織情報の変更 ・証明書記載情報のうち組織の名称その他の組織に関する情報に変更が生じた場合 |
| #4 superseded | 証明書の取替 ・その他の失効事由に該当しない場合において、既存の証明書を取り替える場合 |
| #5 cessationOfOperation | 運用の停止 ・証明書記載情報に含まれるドメイン名の全部または一部について、その管理権限を失った場合 ・Webサイトの停止に伴い証明書を使用しなくなった場合 |
| #9 privilegeWithdrawn | 権限のはく奪 ・証明書利用者がご利用条件に違反した場合 |