Standard X.509 v3 Certificate Extensions
354
Netscape Certificate Management System Plug-Ins Guide • March 2002
Discussion
The Private Key Usage Period extension allows the certificate issuer to specify a
different validity period for the private key than for the certificate itself. This
extension is intended for use with digital signature keys.
PKIX Part 1 recommends against the use of this extension. CAs conforming to
PKIX Part 1 must not generate certificates with this extension.
CMS Version Support
Refer to “PrivateKeyUsagePeriodExt Plug-in Module” on page 228.
•
CMS 4.1
: Not supported
•
CMS 4.2
: Supported
•
CMS 4.2-SP2
: Supported
•
CMS 4.5
: Supported
•
CMS 6.0
: Supported
Netscape Recommendation
Netscape recommends against the use of this extension.
Microsoft Recommendation
Microsoft recommends against the use of this extension.
subjectAltName
OID
2.5.29.17
Reference
http://www.ietf.org/rfc/rfc2459.txt
4.2.1.7
Criticality
If the certificate’s subject field is empty, this extension must be marked critical.
Discussion
The Subject Alternative Name extension includes one or more alternative
(non-X.500) names for the identity bound by the CA to the certified public key. It
may be used in addition to the certificate’s subject name or as a replacement for it.
Defined name forms include Internet electronic mail address (SMTP, as defined in
RFC-822), DNS name, IP address, and uniform resource identifier (URI).
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...