Extensions For Ssl Server Certificate - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Extensions for SSL Server Certificate

You can specify the extensions for an SSL server certificate only if you are installing
a Certificate Manager and you have decided to have that local Certificate Manager
issue the certificate. If the SSL server certificate is issued by a remote CA, its
extensions are determined by the issuing CA.
The default settings should work for most deployments. If necessary, you can add
an additional extension by pasting its base-64 encoding in the space provided on
this screen. For more information about extensions, see Appendix C, "Certificate
and CRL Extensions" of CMS Plug-ins Guide.
Confirm that you want to include the following extensions. Check off all that
apply; defaults are indicated in parentheses.
Basic constraints (No)_____________
CA (Nos)_________
Certification path length (No)_______________________
The certificate chain path length, if specified, determines the maximum
number of certificates in a chain, starting with the end-entity certificate. If you
do not specify this attribute, the length of the chain is unlimited.
Netscape certificate type (Yes)_____________
SSL client (Yes)_________
Object-signing (No)_________
SSL server (Yes)_________
S/MIME CA (No)_________
S/MIME (No)_________
Object-signing CA (No)_________
SSL CA (No)_________
Authority Key Identifier (Yes) ________________
Subject Key Identifier (No)
Key usage (No)_____________
If you decide to include the key usage extension, the following key usage bits
are set by default:
digitalSignature
SSL Server Certificate Configuration
Chapter 5
Installation Worksheet
213

Advertisement

Table of Contents
loading

Table of Contents