Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 451

Table of Contents

Advertisement

Table 10-2 Basic Constraints Extension Default Configuration Parameters
Parameter
Critical
IsCA
PathLen
Description
Select true to mark this extension critical; select false to mark
the extension noncritical.
Specifies whether the certificate subject is a CA. If you select
true, the server checks the PathLen parameter and sets the
specified path length in the certificate. If you select false, the
server treats the certificate subject as a non-CA and ignores the
value specified for the PathLen parameter.
Specifies the path length, the maximum number of CA
certificates that may be chained below (subordinate to) the
subordinate CA certificate being issued. Note that the path
length you specify affects the number of CA certificates to be
used during certificate validation. The chain starts with the
end-entity certificate being validated and moving up the chain.
The maxPathLen parameter has no effect if the extension is set
in end-entity certificates.
Permissible values: 0 or n. Make sure that the value you choose
is less than the path length specified in the Basic Constraints
extension of the CA signing certificate (owned by the CA that
will issue these certificates).
• 0 specifies that no subordinate CA certificates are allowed
below the subordinate CA certificate being issued—that is,
only an end-entity certificate may follow in the path.
• n must be an integer greater than zero. It specifies at the
most n subordinate CA certificates are allowed below the
subordinate CA certificate being used.
If you leave the field blank, the path length defaults to a value
that is determined by the path length set in the Basic
Constraints extension in the issuer's certificate. If the issuer's
path length is unlimited, the path length in the subordinate CA
certificate will also be unlimited. If the issuer's path length is an
integer greater than zero, the path length in the subordinate CA
certificate will be set to a value that's one less than the issuer's
path length; for example, if the issuer's path length is 4, the path
length in the subordinate CA certificate will be set to 3.
Defaults Reference
Chapter 10
Certificate Profiles
451

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents