Page 82 of 226
Version: 3.3.5
– DR05 – 23.03.2017
Subject alternative name
The subject alternative name is a list of alternative names for the certificate holder. These can be RFC822
names (email), DNS names, X.400 addresses, EDI names, URIs or IP addresses. In principle, any structured
naming system is applicable. If using PKIX, this extension is essential when the certificate subject field is empty.
Issuer alternative name
For issuer alternative names, the same applies as for subject alternative names.
CRL distribution point
To be able to use a public access point for certificate revocation lists, you need to enter the LDAP or HTTP ad-
dress of the list. The address should always be prefixed with a
URI
(universal resource indicator) (e.g.
URI:http://de.wikipedia.de). For the field separator, use a colon. If you hold local revocation lists, this option is not
relevant.
Authority Info Access
This PKIX extension defines how to access additional information and services from the issuer of the certificate.
It can then provide more information about the CA (additional guidelines, root certificates ...) or online verification
services (e.g. OCSP). Primarily, where certification applications like secure mail (S/MIME) do not return the en-
tire certification path, using this extension in the end certificate is helpful for showing the verifying application
where to retrieve the next higher level CA certificate.