Subjectaltname - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

Standard X.509 v3 Certificate Extensions

subjectAltName

OID
2.5.29.17
Reference
http://www.ietf.org/rfc/rfc2459.txt
Criticality
If the certificate's subject field is empty, this extension must be marked critical.
Discussion
The Subject Alternative Name extension includes one or more alternative
(non-X.500) names for the identity bound by the CA to the certified public key. It
may be used in addition to the certificate's subject name or as a replacement for it.
Defined name forms include Internet electronic mail address (SMTP, as defined in
RFC-822), DNS name, IP address, and uniform resource identifier (URI).
PKIX requires this extension for entities that are identified by name forms other
than the X.500 distinguished name (DN) used in the subject field. PKIX Part 1
describes additional rules for the relationship between this extension and the
subject field.
Email addresses may be provided either in the Subject Alternative Name
extension, the certificate subject name field, or both. If the email address is
provided as part of the subject name, it must be in the form of the
attribute defined by PKCS-9. Software that supports S/MIME must be able to read
an email address from either the Subject Alternative Name extension or from the
subject name field.
CMS Version Support
Refer to "SubjectAltNameExt Plug-in Module" on page 233.
CMS 4.1: Supported
CMS 4.2: Supported
CMS 4.2-SP2: Supported
Netscape Recommendation
Netscape recommends the use of this extension with all certificates issued by a CA
(except for SSL client certificates).
356
Netscape Certificate Management System Plug-ins Guide • October 2001
4.2.1.7
EmailAddress

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents