Standard X.509 V3 Certificate Extensions - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

Recommendations for Use of Certificate Extensions with CMS (Continued)
Table C-1
Certificate type
CA root
Object
authorityKeyIdentifier
signing/Authe
nticode
certificate
extKeyUsage:
Signing (required for
Authenticode)
keyUsage:
keyCertSign, cRLSign
netscape-cert-type:
Object-signing CA
(required for Object
Signing)
subjectKeyIdentifier

Standard X.509 v3 Certificate Extensions

This section summarizes the extension types that are defined as part of the Internet
X.509 Version 3 standard, as of September 1998, and indicates which types are
recommended by the PKIX working group.
This section summarizes important information about each certificate. For
complete details, see both the X.509 v3 standard (available from the ITU) and the
Internet X.509 Public Key Infrastructure - Certificate and CRL Profile (RFC 2459),
available at
extensions reference the RFC and section number of the standard draft that
discusses the extension; the object identifier (OID) for each extensions is also
provided.
Intermediate CA
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
Code
Signing (required for
Authenticode)
keyUsage:
keyCertSign, cRLSign
netscape-cert-type:
Object-signing CA
(required for Object
Signing)
subjectKeyIdentifier
http://www.ietf.org/rfc/rfc2459.txt
Standard X.509 v3 Certificate Extensions
Issued certificate
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
Code
(required for Authenticode)
keyUsage:
digitalSignature
netscape-cert-type:
Object-signing (required for
Object Signing)
subjectAltName
subjectKeyIdentifier
. The descriptions of
Appendix C
Certificate and CRL Extensions
Code Signing
339

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents