Recommendations for Certificate Extension Use
Recommendations for Use of Certificate Extensions with CMS (Continued)
Table C-1
Certificate type
CA root
SSL server
authorityKeyIdentifier
certificate
extKeyUsage:
Auth (recommended),
Microsoft SGC and
Netscape SGC (required
for step-up)
keyUsage:
keyCertSign, cRLSign
netscape-cert-type:
SSL CA (if extension exists,
bit must be set)
subjectKeyIdentifier
338
Netscape Certificate Management System Plug-ins Guide • October 2001
Intermediate CA
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
Server
Auth (recommended),
Microsoft SGC and
Netscape SGC (required
for step-up)
keyUsage:
keyCertSign, cRLSign
netscape-cert-type:
SSL CA (if extension exists,
bit must be set)
subjectKeyIdentifier
Issued certificate
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
Server
(recommended), Microsoft
SGC and Netscape SGC
(required for step-up)
keyUsage:
keyEncipherment
netscape-cert-type:
SSL Client, SSL Server
(required for some Netscape
servers)
subjectAltName
subjectKeyIdentifier
Server Auth
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 - PLUG-IN and is the answer not in the manual?
Questions and answers