Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual page 739

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Standard X.509 v3 Certificate Extensions
Discussion
This extension, which is for CA certificates only, constrains path validation in two ways. It
can be used to prohibit policy mapping or to require that each certificate in a path contain an
acceptable policy identifier.
PKIX requires that, if present, this extension must never consist of a null sequence. At least
one of the two available fields must be present.
CS Version Support
Supported since CS 4.2. Refer to "PolicyConstraintsExt" on page 531.
policyMappings
OID
2.5.29.33
Criticality
This extension must be noncritical.
Discussion
The Policy Mappings extension is used in CA certificates only. It lists one or more pairs of
OIDs used to indicate that the corresponding policies of one CA are equivalent to policies
of another CA. It may be useful in the context of cross-certification.
This extension may be supported by CAs and/or applications.
CS Version Support
Supported since CS 4.2. Refer to "PolicyMappingsExt" on page 532.
privateKeyUsagePeriod
OID
2.5.29.16
Discussion
The Private Key Usage Period extension allows the certificate issuer to specify a different
validity period for the private key than for the certificate itself. This extension is intended
for use with digital signature keys.
PKIX Part 1 recommends against the use of this extension. CAs conforming to PKIX Part 1
must not generate certificates with this extension.
CS Version Support
Supported since CS 4.2. Refer to "PrivateKeyUsagePeriodExt" on page 534.
Appendix G
Certificate and CRL Extensions
739

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents