Basicconstraints; Certificatepolicies - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

basicConstraints

If this extension is not present, then the issuer name alone is used to identify the issuer certificate.
PKIX Part 1 requires this extension for all certificates except self-signed root CA certificates. Where
a key identifier has not been established, PKIX recommends that the authorityCertIssuer and
authorityCertSerialNumber fields be specified. These fields permit construction of a complete
certificate chain by matching the SubjectName and CertificateSerialNumber fields in the
issuer's certificate against the authortiyCertIssuer and authorityCertSerialNumber in the
Authority Key Identifier extension of the subject certificate.
A.3.3. basicConstraints
A.3.3.1. OID
2.5.29.19
A.3.3.2. Criticality
PKIX Part 1 requires that this extension be marked critical. This extension is evaluated regardless of
its criticality.
A.3.3.3. Discussion
This extension is used during the certificate chain verification process to identify CA certificates and
to apply certificate chain path length constraints. The cA component should be set to true for all CA
certificates. PKIX recommends that this extension should not appear in end-entity certificates.
If the pathLenConstraint component is present, its value must be greater than the number of CA
certificates that have been processed so far, starting with the end-entity certificate and moving up the
chain. If pathLenConstraint is omitted, then all of the higher level CA certificates in the chain must
not include this component when the extension is present.
A.3.4. certificatePolicies
A.3.4.1. OID
2.5.29.32
A.3.4.2. Criticality
This extension may be critical or noncritical.
A.3.4.3. Discussion
The Certificate Policies extension defines one or more policies, each of which consists of an OID and
optional qualifiers. The extension can include a URI to the issuer's Certificate Practice Statement or
can embed issuer information, such as a user notice in text form. This information can be used by
certificate-enabled applications.
If this extension is present, PKIX Part 1 recommends that policies be identified with an OID only, or, if
necessary, only certain recommended qualifiers.
465

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents