Red Hat CERTIFICATE SYSTEM 7.2 - ADMINISTRATION Administration Manual page 481

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - ADMINISTRATION:
Table of Contents

Advertisement

• The certificate's serial number. Every certificate issued by a CA has a serial number that is unique
among the certificates issued by that CA.
• Information about the user's public key, including the algorithm used and a representation of the
key itself.
• The DN of the CA that issued the certificate.
• The period during which the certificate is valid; for example, between 1:00 p.m. on November 15,
2004, and 1:00 p.m. November 15, 2008.
• The DN of the certificate subject, which is also called the subject name; for example, in an SSL
client certificate, this is the user's DN.
• Optional certificate extensions, which may provide additional data used by the client or server. For
example, the Netscape Certificate Type extension indicates the type of certificate, such as an SSL
client certificate, an SSL server certificate, or a certificate for signing email. Certificate extensions
can also be used for other purposes.
• The signature section includes the following information:
• The cryptographic algorithm, or cipher, used by the issuing CA to create its own digital signature.
For more information about ciphers, see
• The CA's digital signature, obtained by hashing all of the data in the certificate together and
encrypting it with the CA's private key.
Here are the data and signature sections of a certificate shown in the readable pretty-print format:
Certificate:
Data:
Version: v3 (0x2)
Serial Number: 3 (0x3)
Signature Algorithm: PKCS #1 MD5 With RSA Encryption
Issuer: OU=Ace Certificate Authority, O=Ace Industry, C=US
Validity:
Not Before: Fri Oct 17 18:36:25 1997
Not
After: Sun Oct 17 18:36:25 1999
Subject: CN=Jane Doe, OU=Finance, O=Ace Industry, C=US
Subject Public Key Info:
Algorithm: PKCS #1 RSA Encryption
Public Key:
Modulus:
00:ca:fa:79:98:8f:19:f8:d7:de:e4:49:80:48:e6:2a:2a:86:
ed:27:40:4d:86:b3:05:c0:01:bb:50:15:c9:de:dc:85:19:22:
43:7d:45:6d:71:4e:17:3d:f0:36:4b:5b:7f:a8:51:a3:a1:00:
98:ce:7f:47:50:2c:93:36:7c:01:6e:cb:89:06:41:72:b5:e9:
73:49:38:76:ef:b6:8f:ac:49:bb:63:0f:9b:ff:16:2a:e3:0e:
9d:3b:af:ce:9a:3e:48:65:de:96:61:d5:0a:11:2a:a2:80:b0:
7d:d8:99:cb:0c:99:34:c9:ab:25:06:a8:31:ad:8c:4b:aa:54:
91:f4:15
Public Exponent: 65537 (0x10001)
Extensions:
Identifier: Certificate Type
Critical: no
Certified Usage:
SSL Client
Identifier: Authority Key Identifier
Section 1.4.10, "SSL/TLS and Supported Cipher
Contents of a Certificate
Suites".
461

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents