Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 743

Table of Contents

Advertisement

Extensions Present
Only
basicConstraints
Only
netscape-cert-type
Neither extension
Both extensions
A certificate chain generally consists of an entity certificate, zero or more
intermediate CA certificates, and a root CA certificate. Typically the root CA
certificate is self-signed and is loaded into Communicator's certificate database as a
trusted CA.
An exchange of certificates takes place when performing an SSL handshake, when
sending an S/MIME message, or when sending a signed object. As part of the
handshake, the sender is expected to send the subject certificate and any
intermediate CA certificates needed to link the subject certificate to the trusted
root. For certificate chaining to work properly the certificates should have the
following properties:
CA certificates must have either the
netscape-cert-type
described above.
If CAs issue multiple certificates for the same identity, for example for separate
signing and encryption keys, they must include the
subject certificates.
Description
The certificate is a CA certificate if the cA component is true.
Path length processing is done as described above.
The certificate is a CA if at least one of the CA bits is set: SSL
CA (5), S/MIME CA (6), or object-signing CA (7). The
certificates issued by this CA are limited to the particular
applications specified. Path length processing is done as
though the pathLenConstraint is unlimited.
The certificate is not a CA.
The certificate is a CA certificate if the cA component of
basicConstraints is true. If one or more of the SSL CA
(5), S/MIME CA (6), or object-signing CA (7) bits are set in
the netscape-cert-type extension, then the CA will be
limited to issuing certificates for the specified application
areas; otherwise, the CA can issue certificates for any
application.
basicConstraints
extension with one or more CA bits set, or both, as
Appendix G
CA Certificates and Extension Interactions
extension, the
extension in the
keyUsage
Certificate and CRL Extensions
743

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents