Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
Parameter
nonRepudiation
keyEncipherment
dataEncipherment
keyAgreement
keyCertsign
cRLSign
encipherOnly
454
Description
from being set; select a hyphen, -, to indicate no
constraints are placed for this parameter.
Specifies whether to set S/MIME signing
certificates. Select true to allow this to be set;
select false to keep this from being set; select
a hyphen, -, to indicate no constraints are placed
for this parameter.
WARNING
Using this bit is controversial.
Carefully consider the legal
consequences of its use before
setting it for any certificate.
Specifies whether to set the extension for SSL
server certificates and S/MIME encryption
certificates. Select true to allow this to be set;
select false to keep this from being set; select
a hyphen, -, to indicate no constraints are placed
for this parameter.
Specifies whether to set the extension when the
subject's public key is used to encrypt user data,
instead of key material. Select true to allow this
to be set; select false to keep this from being
set; select a hyphen, -, to indicate no constraints
are placed for this parameter.
Specifies whether to set the extension whenever
the subject's public key is used for key
agreement. Select true to allow this to be set;
select false to keep this from being set; select
a hyphen, -, to indicate no constraints are placed
for this parameter.
Specifies whether the extension applies for all
CA signing certificates. Select true to allow this
to be set; select false to keep this from being
set; select a hyphen, -, to indicate no constraints
are placed for this parameter.
Specifies whether to set the extension for CA
signing certificates that are used to sign CRLs.
Select true to allow this to be set; select false
to keep this from being set; select a hyphen,
-, to indicate no constraints are placed for this
parameter.
Specifies whether to set the extension if the
public key is to be used only for encrypting data.
If this bit is set, keyAgreement should also be
set. Select true to allow this to be set; select
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?