Bulk Enrollment Interface
Parameters Accepted by the Bulk Enrollment Interface (Continued)
Table 6-7
Parameter
Netscape Certificate
Type Extensions
email
email_ca
object_signing
object_signing_ca
ssl_ca
ssl_client
ssl_server
Key Usage
crl_sign
data_encipherment
decipher_only
122
Netscape Certificate Management System Customization Guide • May 2002
Format and Description
Parameters for setting bits in the netscape-cert-type certificate extension. See
http://home.netscape.com/eng/security/comm4-cert-exts.html for details.
A true value sets the bit to 1; false sets the bit to 0.
true | false
Sets the S/MIME client certificate bit (bit 2).
true | false
Sets the S/MIME certificate issuer bit (bit 6).
true | false
Sets the object signing certificate bit (bit 3).
true | false
Sets the object signing certificate issuer bit (bit 7).
true | false
Sets the SSL certificate issuer bit (bit 5).
true | false
Sets the SSL client authentication certificate bit (bit 0).
true | false
Sets the SSL server authentication certificate bit (bit 1).
Parameters for setting bits in the keyUsage certificate extension. A true
value sets the bit to 1; false sets the bit to 0.
true | false
Sets the keyUsage extension bit (6) indicating that the key may be used to
sign Certificate Revocation Lists (CRLs).
true | false
Sets the keyUsage extension bit (3) indicating that the key may be used to
encipher application data (as opposed to key material).
true | false
Sets the keyUsage extension bit (8) indicating that the key may only be used
to decipher data and keys. If this is true, keyAgreement should also be true.