Extkeyusage - Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual

Table of Contents

Advertisement

Standard X.509 v3 Certificate Extensions
Discussion
This extension defines how CRL information for this certificate is to be obtained. It
should be used if the system is configured to use CRL issuing points.
If the extension contains a
assumed to be a pointer to the current CRL for the associated reasons and will be
issued by the associated
defined for the
reasons, the CRL must include revocations for all reasons. If the
distributionPoint
issued the certificate.
PKIX recommends that this extension be supported by CAs and applications.
CMS Version Support
Refer to "CRLDistributionPointsExt Plug-in Module" on page 163.
CMS 4.1: Supported
CMS 4.2: Supported
CMS 4.2-SP2: Supported
CMS 4.5: Supported
CMS 6.0: Supported
Netscape Recommendation
Netscape recommends that this extension be supported for all certificates, with the
exception of self-signed root CA certificates.
Microsoft Recommendation
Microsoft recommends that this extension be supported.

extKeyUsage

OID
2.5.29.37
Reference
http://www.ietf.org/rfc/rfc2459.txt
344
Netscape Certificate Management System Plug-Ins Guide • March 2002
DistributionPointName
. The expected values for the URI are those
cRLIssuer
extension. If the
subjectAltName
omits
cRLIssuer
of type URI, the URI is
distributionPoint
, the CRL must be issued by the CA that
4.2.1.13
omits

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents