Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
Usage
IPsec user
Timestamping
Table B.4. PKIX Usage Definitions for the Extended Key Usage Extension
Windows 2000 can encrypt files on the hard disk, a feature known as encrypted file system (EFS),
using certificates that contain the Extended Key Usage extension with the following two OIDs:
1.3.6.1.4.1.311.10.3.4 (EFS certificate)
1.3.6.1.4.1.311.10.3.4.1 (EFS recovery certificate)
The EFS recovery certificate is used by a recovery agent when a user loses the private key and the
data encrypted with that key needs to be used. Certificate System supports these two OIDs and allows
certificates to be issued containing the Extended Key Usage extension with these OIDs.
Normal user certificates should be created with only the EFS OID, not the recovery OID.
The following constraints can be defined with this default:
• Extended Key Usage Constraint; see
• Extension Constraint; see
• No Constraints; see
Parameter
Critical
OIDs
Table B.5. Extended Key Usage Extension Default Configuration Parameters
B.1.6. Freshest CRL Extension Default
This default attaches the Freshest CRL extension to the certificate.
The following constraints can be defined with this default:
• Extension Constraint; see
430
Section B.2.2, "Extended Key Usage Extension
Section B.2.3, "Extension
Section B.2.6, "No
Constraint".
Section B.2.3, "Extension
OID
1.3.6.1.5.5.7.3.7
1.3.6.1.5.5.7.3.8
Constraint".
Description
Select true to mark this extension critical; select
false to mark the extension noncritical.
Specifies the OID that identifies a key-usage
purpose. The permissible values are a unique,
valid OID specified in the dot-separated
numeric component notation. For example,
2.16.840.1.113730.1.99. Depending on the key-
usage purposes, the OIDs can be designated
Table B.4, "PKIX Usage
by PKIX (listed in
Definitions for the Extended Key Usage
Extension") or custom OIDs. Custom OIDs must
be in the registered subtree of IDs reserved for
the company's use. Although it is possible to
use custom OIDs for evaluating and testing the
Certificate System, in a production environment,
comply with the ISO rules for defining OIDs and
for registering subtrees of IDs.
Constraint".
Constraint".
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?
Questions and answers