Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
B.3.13. privateKeyUsagePeriod
The Private Key Usage Period extension allows the certificate issuer to specify a different validity
period for the private key than for the certificate itself. This extension is intended for use with digital
signature keys.
NOTE
PKIX Part 1 recommends against the use of this extension. CAs conforming to PKIX Part
1 must not generate certificates with this extension.
OID
2.5.29.16
B.3.14. subjectAltName
The Subject Alternative Name extension includes one or more alternative (non-X.500) names for
the identity bound by the CA to the certified public key. It may be used in addition to the certificate's
subject name or as a replacement for it. Defined name forms include Internet electronic mail address
(SMTP, as defined in RFC-822), DNS name, IP address (both IPv4 and IPv6), and uniform resource
identifier (URI).
PKIX requires this extension for entities identified by name forms other than the X.500 distinguished
name (DN) used in the subject field. PKIX Part 1 describes additional rules for the relationship
between this extension and the subject field.
Email addresses may be provided in the Subject Alternative Name extension, the certificate subject
name field, or both. If the email address is part of the subject name, it must be in the form of the
EmailAddress attribute defined by PKCS #9. Software that supports S/MIME must be able to read
an email address from either the Subject Alternative Name extension or from the subject name field.
OID
2.5.29.17
Criticality
If the certificate's subject field is empty, this extension must be marked critical.
B.3.15. subjectDirectoryAttributes
The Subject Directory Attributes extension conveys any desired directory attribute values for the
subject of the certificate. It is not recommended as an essential part of the proposed PKIX standard
but may be used in local environments.
OID
2.5.29.9
Criticality
PKIX Part 1 requires that this extension be marked noncritical.
466
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?
Questions and answers