Standard X.509 v3 Certificate Extensions
342
Netscape Certificate Management System Plug-Ins Guide • March 2002
Criticality
PKIX Part 1 requires that this extension be marked critical. This extension is
evaluated regardless of its criticality.
Discussion
This extension is used during the certificate chain verification process to identify
CA certificates and to apply certificate chain path length constraints. The
cA
component should be set to true for all CA certificates. PKIX recommends that this
extension should not appear in end-entity certificates.
If the
pathLenConstraint
component is present, its value must be greater than the
number of CA certificates that have been processed so far (starting with the
end-entity certificate and moving up the chain). If
pathLenConstraint
is omitted,
then all of the higher level CA certificates in the chain must not include this
component when the extension is present.
See “CA Certificates and Extension Interactions” on page 368 regarding the
interaction of
the
this extension with the Netscape Certificate Type extension.
CMS Version Support
Refer to “BasicConstraintsExt Plug-in Module” on page 144.
•
CMS 4.1
: Supported
•
CMS 4.2
: Supported
•
CMS 4.2-SP2
: Supported
•
CMS 4.5
: Supported
•
CMS 6.0
: Supported
Netscape Recommendation
Netscape requires this extension for all CA certificates.
Microsoft Recommendation
Microsoft recommends this extension for all certificates.
certificatePolicies
OID
2.5.29.32
References
http://www.ietf.org/rfc/rfc2459.txt
4.2.1.5
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...