Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual page 759

Table of Contents

Advertisement

Standard X.509 v3 Certificate Extensions
by matching the
and
fields in the
SubjectName
CertificateSerialNumber
issuer's certificate against the
and
authortiyCertIssuer
in the
extension of the
authorityCertSerialNumber
AuthorityKeyIdentifier
subject certificate.
CMS Version Support
Supported since CMS 4.1. Refer to "AuthorityKeyIdentifierExt" on page 511.
Note that CMS does not use or support the
field in
authorityCertSerialNumber
the Authority Key Identifier extension.
basicConstraints
OID
2.5.29.19
Criticality
PKIX Part 1 requires that this extension be marked critical. This extension is
evaluated regardless of its criticality.
Discussion
This extension is used during the certificate chain verification process to identify
CA certificates and to apply certificate chain path length constraints. The
cA
component should be set to true for all CA certificates. PKIX recommends that this
extension should not appear in end-entity certificates.
If the
component is present, its value must be greater than the
pathLenConstraint
number of CA certificates that have been processed so far (starting with the
end-entity certificate and moving up the chain). If
is omitted,
pathLenConstraint
then all of the higher level CA certificates in the chain must not include this
component when the extension is present.
See "CA Certificates and Extension Interactions" on page 776 regarding the
interaction of
this extension with the Netscape Certificate Type extension.
the
CMS Version Support
Supported since CMS 4.1. Refer to "BasicConstraintsExt" on page 512.
certificatePolicies
OID
2.5.29.32
Appendix G
Certificate and CRL Extensions
759

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents