Basic Constraints Extension Default - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Basic Constraints Extension Default

This default populates Basic Constraint extension in the certificate request. The extension
identifies whether or not the Certificate Manager is a CA. The extension is also used during
the certificate chain verification process to identify CA certificates and to apply certificate
chain-path length constraints.
For general information about this extension, see "basicConstraints" on page 732.
You can define the following constraints with this default:
Basic Constraints Extension Constraint, see "Basics Constraints Extension Constraint,"
on page 453
Extension Constraint, see "Extension Constraint," on page 454
No Constraints, see "No Constraint," on page 456.
Table 11-2
Basic Constraints Extension Default Configuration Parameters
Parameter
Critical
IsCA
PathLen
Description
Select true to mark this extension critical; select false to mark the
extension noncritical.
Specifies whether the certificate subject is a CA. If you select true, the
server checks the PathLen parameter and sets the specified path
length in the certificate. If you select false, the server treats the
certificate subject as a non-CA and ignores the value specified for the
PathLen parameter.
Specifies the path length, the maximum number of CA certificates that
may be chained below (subordinate to) the subordinate CA certificate
being issued. Note that the path length you specify affects the number
of CA certificates to be used during certificate validation. The chain
starts with the end-entity certificate being validated and moving up the
chain.
The maxPathLen parameter has no effect if the extension is set in
end-entity certificates.
Permissible values: 0 or n. Make sure that the value you choose is less
than the path length specified in the Basic Constraints extension of the
CA signing certificate (owned by the CA that will issue these
certificates).
0 specifies that no subordinate CA certificates are allowed below
the subordinate CA certificate being issued—that is, only an
end-entity certificate may follow in the path.
Defaults Reference
Chapter 11
Certificate Profiles
431

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents