Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual page 332

Table of Contents

Advertisement

Recommendations for Certificate Extension Use
cRLDistributionPoints. Defines how CRL information for the certificate is to be
obtained.
extKeyUsage. Indicates purpose or purposes for which the certificate may be used,
either in addition to or instead of the purposes indicated by the keyUsage
extension.
keyUsage. Indicates the purpose or purposes for which the public key certified by
the certificate may be used.
netscape-cert-type. Indicates the purpose or purposes for which the certificate may
be used. Required only for compatibility with some Netscape products that were
released before by X.509 v3 was finalized.
subjectAltName. Specifies one or more alternative names for the identity bound by
the CA to the certified public key.
subjectKeyIdentifier. Identifies the public key certified by the certificate.
These extensions, plus others, are described in detail in later sections of this
appendix. Additional extensions may be useful for a variety of purposes. However,
the extensions listed above are either required or recommended for various kinds
of certificates issued by Certificate Management System.
Table C-1 summarizes guidelines for using these extensions. The table provides a
summary only. Each extension is explained in detail later in the Appendix. Keep
the following in mind as you use the table:
Using certificate extensions incorrectly can lead to severe deployment
problems. Make sure you have thoroughly analyzed your deployment needs
and completely understand the purpose of each extension you want to use
before adding them to certificates.
Unless otherwise noted in Table C-1, the extensions indicated should be
included with certificates of each type to ensure compatibility with both PKIX
Part 1 and with future Netscape products.
Extensions marked "required" must be supported for some existing Netscape
or Microsoft products or for other reasons explained in the extenstion
descriptions that follow.
332
Netscape Certificate Management System Plug-Ins Guide • March 2002

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents