Page 88 of 226
Version: 3.3.5
– DR05 – 23.03.2017
Subject alternative name
The subject alternative name is a list of alternative names for the certificate holder. These can be RFC822
names (email), DNS names, X.400 addresses, EDI names, URIs or IP addresses. In principle, any structured
naming system is applicable. If using PKIX, this extension is essential when the certificate subject field is empty.
Issuer alternative name
For issuer alternative names, the same applies as for subject alternative names.
CRL distribution point
To be able to use a public access point for certificate revocation lists, you need to enter the LDAP / or HTTP
address of the list. The address should always be prefixed with a
URI
(universal resource indicator) (e.g.
URI:http://de.wikipedia.de). For the field separator, use a colon. If you hold local revocation lists, this option is not
relevant.
Authority Info Access
This PKIX extension defines how to access additional information and services from the issuer of the certifi-
cate. It can then provide more information about the CA (additional guidelines, root certificates ...) or online veri-
fication services (e.g. OCSP). Primarily, where certification applications like secure mail (S/MIME) do not return
the entire certification path, using this extension in the end certificate is helpful for showing the verifying applica-
tion where to retrieve the next higher level CA certificate.
Client certificate
– Key usage
13.2.2.4
If you create a client certificate as an end entity, you do not need any of these optional settings. You can
proceed straight to the next tab.