Standard X.509 v3 Certificate Extensions
Appendix
C
Certificate and CRL Extensions
341
PKIX Part 1 requires this extension for all certificates except self-signed root CA
certificates. Where a key identifier has not been previously established, PKIX
recommends that the
authorityCertIssuer
and
authorityCertSerialNumber
fields be specified. These fields permit construction of a complete certificate chain
by matching the
SubjectName
and
CertificateSerialNumber
fields in the
issuer’s certificate against the
authortiyCertIssuer
and
authorityCertSerialNumber
in the
AuthorityKeyIdentifier
extension of the
subject certificate.
CMS Version Support
Refer to “AuthorityKeyIdentifierExt Plug-in Module” on page 141.
•
CMS 4.1
: Supported
•
CMS 4.2
: Supported
•
CMS 4.2-SP2
: Supported
•
CMS 4.5
: Supported
•
CMS 6.0
: Supported
Note that Certificate Management System does not use or support the
authorityCertSerialNumber
field in the Authority Key Identifier extension.
Netscape Recommendation
Netscape recommends that this extension be present in all certificates and that the
authorityCertIssuer
and
authorityCertSerialNumber
fields be specified. This
extension is not supported by Navigator 3.x, but its presence in a certificate won’t
interfere with Navigator 3.x.
Microsoft Recommendation
Microsoft recommends that this extension be present in all certificates and that the
authorityCertIssuer
and
authorityCertSerialNumber
fields be specified.
basicConstraints
OID
2.5.29.19
Reference
http://www.ietf.org/rfc/rfc2459.txt
4.2.1.10
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...