Key Usage Extension Default - Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
Parameter
Table B.7. Issuer Alternative Name Extension Default Configuration Parameters
B.1.8. Key Usage Extension Default
This default attaches the Key Usage extension to the certificate. The extension specifies the purposes
for which the key contained in a certificate should be used, such as data signing, key encryption, or
data encryption, which restricts the usage of a key pair to predetermined purposes.
For general information about this extension, see
The following constraints can be defined with this default:
• Key Usage Constraint; see
• Extension Constraint; see
• No Constraints; see
Parameter
critical
digitalSignature
nonRepudiation
keyEncipherment
dataEncipherment
keyAgreement
keyCertsign
434
Section B.2.5, "Key Usage Extension
Section B.2.3, "Extension
Section B.2.6, "No
Constraint".
Description
the issuerAlternativeName, then literal string
can be used without any token expression. For
example, Certificate Authority.
Section B.3.8,
"keyUsage".
Constraint".
Constraint".
Description
Select true to mark this extension critical; select
false to mark the extension noncritical.
Specifies whether to allow signing SSL client
certificates and S/MIME signing certificates.
Select true to set.
Specifies whether to use for S/MIME signing
certificates. Select true to set.
WARNING
Using this bit is controversial.
Carefully consider the legal
consequences of its use before
setting it for any certificate.
Specifies whether the public key in the subject
is used to encipher private or secret keys. This
is set for SSL server certificates and S/MIME
encryption certificates. Select true to set.
Specifies whether to set the extension when the
subject's public key is used to encipher user data
as opposed to key material. Select true to set.
Specifies whether to set the extension whenever
the subject's public key is used for key
agreement. Select true to set.
Specifies whether the public key is used to verify
the signature of other certificates. This setting is

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents