Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 457

Table of Contents

Advertisement

For general information about this extension, see "keyUsage" on page 728.
You can define the following constraints with this default:
Key Usage Constraint, see "Key Usage Extension Constraint," on page 475.
Extension Constraint, see "Extension Constraint," on page 475.
No Constraints, see "No Constraint," on page 477.
Table 10-7 Key Usage Extension Default Configuration Parameters
Parameter
critical
digitalSignature
nonRepudiation
keyEncipherment
dataEncipherment
keyAgreement
keyCertsign
cRLSign
encipherOnly
Description
Select true to mark this extension critical; select false to mark the
extension noncritical.
Specifies whether to allow for signing of SSL client certificates,
S/MIME signing certificates, and object-signing certificates.
Select true to set, select false to not set.
Specifies whether to some S/MIME signing certificates and
object-signing certificates. Note, however, that the use of this bit
is controversial. You should carefully consider the legal
consequences of its use before setting it for any certificate. Select
true to set, select false to not set.
Specifies whether to set the extension for SSL server certificates
and S/MIME encryption certificates. Select true to set, select
false to not set.
Specifies whether to set the extension when the subjects's public
key is used to encipher user data (as opposed to key material).
Select true to set, select false to not set.
Specifies whether to set the extension whenever the subject's
public key is used for key agreement. Select true to set, select
false to not set.
Specifies whether extension for all CA signing certificates. Select
true to set, select false to not set.
Specifies whether to set the extension for CA signing certificates
that are used to sign CRLs. Select true to set, select false to
not set.
Specifies whether to set the extension if the public key is to be
used only for enciphering data. If this bit is set, keyAgreement
should also be set. Select true to set, select false to not set.
Defaults Reference
Chapter 10
Certificate Profiles
457

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents