Extended Key Usage Extension Constraint - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Constraints Reference
Table 10-18 Basic Constraints Extension Constraint Configuration Parameters (Continued)
Parameter
PathLen

Extended Key Usage Extension Constraint

The extended key usage extension constraint checks if the extended key usage
extension in the certificate request satisfies the criteria set in this constraint.
474
Netscape Certificate Management System Administrator's Guide • February 2003
Description
Specifies the maximum allowable path length, the maximum
number of CA certificates that may be chained below
(subordinate to) the subordinate CA certificate being issued.
Note that the path length you specify affects the number of CA
certificates to be used during certificate validation. The chain
starts with the end-entity certificate being validated and
moving up the chain.
This parameter has no effect if the extension is set in end-entity
certificates.
Permissible values: 0 or n. Make sure that the value you choose
is less than the path length specified in the Basic Constraints
extension of the CA signing certificate (owned by the CA that
will issue these certificates).
• 0 specifies that no subordinate CA certificates are allowed
below the subordinate CA certificate being issued—that is,
only an end-entity certificate may follow in the path.
• n must be an integer greater than zero. It specifies at the
most n subordinate CA certificates are allowed below the
subordinate CA certificate being used.
If you leave the field blank, the path length defaults to a
value that is determined by the path length set on the
Basic Constraints extension in the issuer's certificate. If
the issuer's path length is unlimited, the path length in
the subordinate CA certificate will also be unlimited. If
the issuer's path length is an integer greater than zero,
the path length in the subordinate CA certificate will be
set to a value that's one less than the issuer's path length;
for example, if the issuer's path length is 4, the path
length in the subordinate CA certificate will be set to 3.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents