Recommendations for Certificate Extension Use
Appendix
C
Certificate and CRL Extensions
331
Note that not all applications support certificates with version 3 extensions.
Applications that do support these extensions may not be able to interpret some or
all of these specific extensions.
Sample Certificate Extensions
The following is an example of the section of a certificate containing X.509 v3
extensions. (Certificate Management System can display certificates in
human-readable format, as shown here.) As shown in the example, certificate
extensions appear in sequence and only one instance of a particular extension may
appear in a particular certificate; for example, a certificate may contain only one
subject key identifier extension. Note that certificates that support these extensions
have the version 0x2 (which corresponds to version 3).
Certificate:
Data:
Version: v3 (0x2)
...
Extensions:
Identifier: Certificate Type
Critical: no
Certified Usage:
SSL CA
Identifier: Subject Key Identifier
Critical: no
Value:
2c:22:c6:ae:4e:4b:91:c7:fb:4c:cc:ae:84:e8:aa:5b:46:6a:a0:ad
Identifier: Authority Key Identifier
Critical: no
Key Identifier:
2c:22:c6:ae:4e:4b:91:c7:fb:4c:cc:ae:84:e8:aa:5b:46:6a:a0:ad
Recommendations for Certificate Extension Use
Most deployments will use some or all of these extensions:
authorityKeyIdentifier.
Identifies the public key corresponding to the private key
used to sign a certificate.
basicConstraints.
Identifies CA certificates and optionally specifies a maximum
certificate chain path length.
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...