Standard X.509 v3 Certificate Extensions
Table C-3
Use
Certificate trust list signing
Microsoft Server Gated
Crypto (SGC)
Microsoft Encrypted File
System
Netscape SGC
CMS Version Support
Refer to "ExtendedKeyUsageExt Plug-in Module" on page 168.
•
CMS 4.1: Not supported
•
CMS 4.2: Supported
•
CMS 4.2-SP2: Supported
•
CMS 4.5: Supported
•
CMS 6.0: Supported
Netscape Recommendations
Netscape recommends that this extension be supported for all certificates, and
requires it for all certificates that support step-up, or Server Gated Crypto (SGC).
OCSP Signing should be included in all certificates issued to OCSP responders.
Microsoft Recommendations
Microsoft products interpret this extension as follows. If the extension is not
present, the certificate is considered to be valid for any usage (to support backward
compatibility with certificates that did not use this extension). Otherwise,
interpretation depends on usage, as follows:
•
Authenticode requires that Code Signing be the unique usage specified.
•
SGC operation requires that the SGC usage be specified.
•
Timestamping requires that timestamping usage be specified.
346
Netscape Certificate Management System Plug-Ins Guide • March 2002
Private Extended Key Usage Extension Uses
OID
1.3.6.1.4.1.311.10.3.1
1.3.6.1.4.1.311.10.3.3
1.3.6.1.4.1.311.10.3.4
2.16.840.1.113730.4.1
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.0 - PLUG-IN and is the answer not in the manual?
Questions and answers