Chapter 12. Certificate Profiles
The EFS recovery certificate is used by a recovery agent when a user loses the private key and the
data encrypted with that key needs to be used. Certificate System supports these two OIDs and allows
certificates to be issued containing the Extended Key Usage extension with these OIDs.
Normal user certificates should be created with only the EFS OID, not the recovery OID.
The following constraints can be defined with this default:
• Extended Key Usage Constraint; see
• Extension Constraint; see
Section 12.8.6, "No
• No Constraints; see
Parameter
Critical
OIDs
Table 12.7. Extended Key Usage Extension Default Configuration Parameters
12.7.6. Freshest CRL Extension Default
This default attaches the Freshest CRL extension to the certificate.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 12.8.6, "No
• No Constraints; see
This default defines five locations with parameters for each location. The parameters are marked with
an n in the table to show with which location the parameter is associated.
Parameter
Critical
PointEnable_n
PointType_n
264
Section 12.8.2, "Extended Key Usage Extension
Section 12.8.3, "Extension
Constraint".
Section 12.8.3, "Extension
Constraint".
Constraint".
Constraint".
Constraint".
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?