<html xmlns="http://www.w3.org/1999/xhtml"><head></head><body><figure class="quote"><figcaption><p><anchor-end xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:anchor="1" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:">[1]</anchor-end> <cite xml:lang="en">RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</cite>
(<time>2015-02-22 15:44:10 +09:00</time> 版)
<anchor-external xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resScheme="URI" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resParameter="http://tools.ietf.org/html/rfc5280#section-4.2.1.6">http://tools.ietf.org/html/rfc5280#section-4.2.1.6</anchor-external></p></figcaption><blockquote><p>When the subjectAltName extension contains an Internet mail address,</p><p>the address MUST be stored in the rfc822Name.  The format of an</p><p>rfc822Name is a &quot;Mailbox&quot; as defined in Section 4.1.2 of <strong>[</strong>RFC2821<strong>]</strong>.</p><p>A Mailbox has the form &quot;Local-part@Domain&quot;. </p></blockquote></figure><figure class="quote"><figcaption><p><anchor-end xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:anchor="2" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:">[2]</anchor-end> <cite xml:lang="en">RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</cite>
(<time>2015-02-22 15:44:10 +09:00</time> 版)
<anchor-external xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resScheme="URI" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resParameter="http://tools.ietf.org/html/rfc5280#section-4.2.1.10">http://tools.ietf.org/html/rfc5280#section-4.2.1.10</anchor-external></p></figcaption><blockquote><p>A name constraint for Internet mail addresses MAY specify a</p><p>particular mailbox, all addresses at a particular host, or all</p><p>mailboxes in a domain.  To indicate a particular mailbox, the</p><p>constraint is the complete mail address.  For example,</p><p>&quot;root@example.com&quot; indicates the root mailbox on the host</p><p>&quot;example.com&quot;.  To indicate all Internet mail addresses on a</p><p>particular host, the constraint is specified as the host name.  For</p><p>example, the constraint &quot;example.com&quot; is satisfied by any mail</p><p>address at the host &quot;example.com&quot;.  To specify any address within a</p><p>domain, the constraint is specified with a leading period (as with</p><p>URIs).  For example, &quot;.example.com&quot; indicates all the Internet mail</p><p>addresses in the domain &quot;example.com&quot;, but not Internet mail</p><p>addresses on the host &quot;example.com&quot;.</p></blockquote></figure><figure class="quote"><figcaption><p><anchor-end xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:anchor="3" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:">[3]</anchor-end> <cite xml:lang="en">RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</cite>
(<time>2015-02-22 15:44:10 +09:00</time> 版)
<anchor-external xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resScheme="URI" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resParameter="http://tools.ietf.org/html/rfc5280#section-4.2.1.10">http://tools.ietf.org/html/rfc5280#section-4.2.1.10</anchor-external></p></figcaption><blockquote><p>Legacy implementations exist where an electronic mail address is</p><p>embedded in the subject distinguished name in an attribute of type</p><p>emailAddress (Section 4.1.2.6).  When constraints are imposed on the</p><p>Cooper, et al.              Standards Track                    <strong>[</strong>Page 41<strong>]</strong></p><p>page-42 </p><p>RFC 5280            PKIX Certificate and CRL Profile            May 2008</p><p>rfc822Name name form, but the certificate does not include a subject</p><p>alternative name, the rfc822Name constraint MUST be applied to the</p><p>attribute of type emailAddress in the subject distinguished name.</p></blockquote></figure><figure class="quote"><figcaption><p><anchor-end xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:anchor="4" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:">[4]</anchor-end> <cite xml:lang="en">RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</cite>
(<time>2015-02-22 15:44:10 +09:00</time> 版)
<anchor-external xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resScheme="URI" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resParameter="http://tools.ietf.org/html/rfc5280#section-7.5">http://tools.ietf.org/html/rfc5280#section-7.5</anchor-external></p></figcaption><blockquote><p>Where the host-part (the Domain of the Mailbox) contains an</p><p>internationalized name, the domain name MUST be converted from an IDN</p><p>to the ASCII Compatible Encoding (ACE) format as specified in Section</p><p>7.2.</p><p>Two email addresses are considered to match if:</p><p>1)  the local-part of each name is an exact match, AND</p><p>2)  the host-part of each name matches using a case-insensitive</p><p>ASCII comparison.</p><p>Implementations should convert the host-part of internationalized</p><p>email addresses specified in these extensions to Unicode before</p><p>display.  Specifically, conforming implementations should perform the</p><p>conversion of the host-part of the Mailbox as described in Section</p><p>7.2.</p></blockquote></figure></body></html>