Recommendations for Certificate Extension Use
Appendix
C
Certificate and CRL Extensions
333
Table C-1
Recommendations for Use of Certificate Extensions with CMS
Certificate type
CA root
Intermediate CA
Issued certificate
SSL client
certificate
authorityKeyIdentifier
basicConstraints:
true
(required)
extKeyUsage:
client auth
keyUsage:
keyCertSign
,
cRLSign
netscape-cert-type:
SSL CA (if extension exists,
bit must be set)
subjectKeyIdentifier
authorityKeyIdentifier
basicConstraints:
true
(required)
cRLDistributionPoints
extKeyUsage:
client auth
keyUsage:
keyCertSign
,
cRLSign
netscape-cert-type:
SSL CA (required for client
authentication with some
Netscape servers)
subjectKeyIdentifier
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
client auth
keyUsage:
digitalSignature
netscape-cert-type:
SSL client (if extension exists,
bit must be set; otherwise, not
required)
subjectKeyIdentifier
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...