Standard X.509 v3 CRL Extensions
...
Standard X.509 v3 CRL Extensions
In addition to certificate extensions, the X.509 v3 proposed standard defines extensions to
CRLs, which provide methods for associating additional attributes with Internet CRLs.
These are of two kinds: extensions to the CRL itself, and extensions to individual certificate
entries in the CRL.
•
Extensions for CRLs
•
CRL Entry Extensions
Extensions for CRLs
The sections that follow describe the CRL extension types that are defined as part of the
Internet X.509 v3 Public Key Infrastructure proposed standard, as of September 1998.
These are the CRL extensions described in the sections that follow:
•
authorityKeyIdentifier
•
CRLNumber
•
deltaCRLIndicator
•
issuerAltName
•
issuingDistributionPoint
authorityKeyIdentifier
OID
2.5.29.35
Discussion
The Authority Key Identifier extension for a CRL identifies the public key corresponding to
the private key used to sign the CRL. For details, see the discussion under certificate
extensions at authorityKeyIdentifier.
CS Version Support
Supported since CS 4.2. Refer to "AuthorityKeyIdentifier" on page 583.
744
Red Hat Certificate System Administrator's Guide • September 2005
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?