Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual page 734

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Standard X.509 v3 Certificate Extensions
Criticality
PKIX recommends that this extension be marked noncritical and that it be supported for all
certificates.
Discussion
This extension defines how CRL information for this certificate is to be obtained. It should
be used if the system is configured to use CRL issuing points.
If the extension contains a
be a pointer to the current CRL for the associated reasons and will be issued by the
associated
subjectAltName
include revocations for all reasons. If the
CRL must be issued by the CA that issued the certificate.
PKIX recommends that this extension be supported by CAs and applications.
CS Version Support
Supported since CS 4.1. Refer to "CRLDistributionPointsExt" on page 501.
extKeyUsage
OID
2.5.29.37
Criticality
If this extension is marked critical, the certificate must be used for one of the indicated
purposes only. If it is not marked critical, it is treated as an advisory field that may be used
to identify keys but does not restrict the use of the certificate to the indicated purposes.
Discussion
The Extended Key Usage extension indicates one or more purposes for which the certified
public key may be used. These purposes may be in addition to or in place of the basic
purposes indicated in the key usage extension.
The Extended Key Usage extension must include OCSP Signing in an OCSP responder's
certificate (unless the CA signing key that signed the certificates validated by the responder
is also the OCSP signing key). The OCSP responder's certificate must be issued directly by
the CA that signs certificates the responder will validate.
The Key Usage, Extended Key Usage, and Basic Constraints extensions act together to
define the purposes for which the certificate is intended to be used. Applications can use
these extensions to disallow the use of a certificate in inappropriate contexts.
734
Red Hat Certificate System Administrator's Guide • September 2005
DistributionPointName
. The expected values for the URI are those defined for the
cRLIssuer
extension. If the
of type URI, the URI is assumed to
distributionPoint
distributionPoint
omits reasons, the CRL must
omits
cRLIssuer
, the

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents