Crl Distribution Points Extension Default - Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
Parameter
Critical
IsCA
PathLen
Table B.2. Basic Constraints Extension Default Configuration Parameters
B.1.4. CRL Distribution Points Extension Default
This default attaches the CRL Distribution Points extension to the certificate. This extension identifies
locations from which an application that is validating the certificate can obtain the CRL information to
verify the revocation status of the certificate.
426
Description
Select true to mark this extension critical; select
false to mark the extension noncritical.
Specifies whether the certificate subject is a
CA. With true, the server checks the PathLen
parameter and sets the specified path length in
the certificate. With false, the server treats the
certificate subject as a non-CA and ignores the
value specified for the PathLen parameter.
Specifies the path length, the maximum number
of CA certificates that may be chained below
(subordinate to) the subordinate CA certificate
being issued. The path length affects the number
of CA certificates to be used during certificate
validation. The chain starts with the end-entity
certificate being validated and moves up.
The maxPathLen parameter has no effect if the
extension is set in end-entity certificates.
The permissible values are 0 or n. The value
should be less than the path length specified
in the Basic Constraints extension of the
CA signing certificate. 0 specifies that no
subordinate CA certificates are allowed below
the subordinate CA certificate; only an end-
entity certificate may follow in the path. n must
be an integer greater than zero. It specifies the
maximum number of subordinate CA certificates
allowed below the subordinate CA certificate.
If the field is blank, the path length defaults to
a value that is determined by the path length
set in the Basic Constraints extension in the
issuer's certificate. If the issuer's path length is
unlimited, the path length in the subordinate CA
certificate will also be unlimited. If the issuer's
path length is an integer greater than zero, the
path length in the subordinate CA certificate will
be set to a value that's one less than the issuer's
path length; for example, if the issuer's path
length is 4, the path length in the subordinate CA
certificate will be set to 3.

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents