327
Appendix
C
Certificate and CRL Extensions
This appendix explains both the standard certificate extensions defined by X.509 v3
and the extensions defined by Netscape that were used in versions of products
released before X.509 v3 was finalized. It also provides recommendations for
extensions to use with specific kinds of certificates, including both PKIX Part 1
recommendations and Netscape extensions that must be supported for
compatibility with early versions of Netscape products.
This appendix contains the following sections:
•
Introduction to Certificate Extensions (page 327)
•
Recommendations for Certificate Extension Use (page 331)
•
Standard X.509 v3 Certificate Extensions (page 337)
•
Introduction to CRL Extensions (page 357)
•
Standard X.509 v3 CRL Extensions (page 360)
•
Netscape-Defined Certificate Extensions (page 366)
•
CA Certificates and Extension Interactions (page 368)
Introduction to Certificate Extensions
An X.509 v3 certificate contains an extensions field that permits any number of
additional fields to be added to the certificate. Certificate extensions provide a way
of adding information such as alternative subject names and usage restrictions to
certificates. Older versions of Netscape browsers and servers that were developed
before PKIX part 1 standards were defined require Netscape-specific extensions.
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...