legal usage combinations). There must be a one-to-one mapping between certificate
requests and certificates. The same certificate request can be used to obtain multiple
certificates; however, more than one certificate for each certificate request cannot be
installed in the same wallet at the same time.
Oracle Wallet Manager uses the X.509 Version 3 KeyUsage extension to define
Oracle PKI certificate usages
Table 8–1 KeyUsage Values
Value Usage
0
digitalSignature
1
nonRepudiation
2
keyEncipherment
3
dataEncipherment
4
keyAgreement
5
keyCertSign
6
cRLSign
7
encipherOnly
8
decipherOnly
When installing a certificate (user certificate or
Manager maps the KeyUsage extension values to Oracle PKI certificate usages as
specified in
Table 8–2
Table 8–2 Oracle Wallet Manager Import of User Certificates to an Oracle Wallet
KeyUsage Value
none
0 alone, or any combination
including 0 but excluding 5
and 2
1 alone
(Table
8–1):
and
Table
8–3.
1
Critical?
Usage
na
Certificate is importable for SSL or S/MIME
encryption use.
na
Accept certificate for S/MIME signature or
code-signing use.
Yes
Not importable.
No
Accept certificate for S/MIME signature or
code-signing use.
Oracle Wallet Manager Overview
trusted
certificate), Oracle Wallet
Using Oracle Wallet Manager 8-5
Need help?
Do you have a question about the Oracle Database B10772-01 and is the answer not in the manual?