Sample Certificate Extensions; Recommendations For Certificate Extension Use - Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual

Table of Contents

Advertisement

Note that not all applications support certificates with version 3 extensions.
Applications that do support these extensions may not be able to interpret some or
all of these specific extensions.

Sample Certificate Extensions

The following is an example of the section of a certificate containing X.509 v3
extensions. (Certificate Management System can display certificates in
human-readable format, as shown here.) As shown in the example, certificate
extensions appear in sequence and only one instance of a particular extension may
appear in a particular certificate; for example, a certificate may contain only one
subject key identifier extension. Note that certificates that support these extensions
have the version 0x2 (which corresponds to version 3).
Certificate:
Data:
...
Extensions:
Identifier: Certificate Type
Identifier: Subject Key Identifier
Identifier: Authority Key Identifier

Recommendations for Certificate Extension Use

Most deployments will use some or all of these extensions:
authorityKeyIdentifier. Identifies the public key corresponding to the private key
used to sign a certificate.
basicConstraints. Identifies CA certificates and optionally specifies a maximum
certificate chain path length.
Version: v3 (0x2)
Critical: no
Certified Usage:
SSL CA
Critical: no
Value:
2c:22:c6:ae:4e:4b:91:c7:fb:4c:cc:ae:84:e8:aa:5b:46:6a:a0:ad
Critical: no
Key Identifier:
2c:22:c6:ae:4e:4b:91:c7:fb:4c:cc:ae:84:e8:aa:5b:46:6a:a0:ad
Recommendations for Certificate Extension Use
Appendix C
Certificate and CRL Extensions
331

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents