Subjectkeyidentifier - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

Standard X.509 v3 Certificate Extensions
Microsoft Recommendation
Microsoft products do not examine this extension.

subjectKeyIdentifier

OID
2.5.29.14
Reference
http://www.ietf.org/rfc/rfc2459.txt
Criticality
This extension is always noncritical.
Discussion
The Subject Key Identifier extension identifies the public key certified by this
certificate. This extension provides a way of distinguishing public keys if more
than one is available for a given subject name, for example after the certificate has
been renewed with a new key.
The value of this extension should be calculated by performing a SHA-1 hash of the
certificate's DER-encoded
Subject Key Identifier extension is used in conjunction with the Authority Key
Identifier extension for CA certificates. If the CA certificate has a Subject Key
Identifier extension, the key identifier in the Authority Key Identifier extension (of
the certificate being verified) should match the key identifier of the CA's Subject
Key Identifier extension. It is not necessary for the verifier to recompute the key
identifier in this case.
PKIX Part 1 requires this extension for all CA certificates and recommends it for all
other certificates.
CMS Version Support
Refer to "SubjectKeyIdentifierExt Plug-in Module" on page 243.
CMS 4.1: Supported
CMS 4.2: Supported
CMS 4.2-SP2: Supported
Netscape Recommendation
Netscape recommends this extension for all certificates.
358
Netscape Certificate Management System Plug-ins Guide • October 2001
4.2.1.2
, as recommended by PKIX. The
subjectPublicKey

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents