Standard X.509 v3 Certificate Extensions
Appendix
C
Certificate and CRL Extensions
337
Standard X.509 v3 Certificate Extensions
This section summarizes the extension types that are defined as part of the Internet
X.509 Version 3 standard, as of September 1998, and indicates which types are
recommended by the PKIX working group.
This section summarizes important information about each certificate. For
complete details, see both the X.509 v3 standard (available from the ITU) and the
Internet X.509 Public Key Infrastructure - Certificate and CRL Profile (RFC 2459),
available at
http://www.ietf.org/rfc/rfc2459.txt
. The descriptions of
extensions reference the RFC and section number of the standard draft that
discusses the extension; the object identifier (OID) for each extensions is also
provided.
Object
signing/Authe
nticode
certificate
authorityKeyIdentifier
extKeyUsage:
Code
Signing (required for
Authenticode)
keyUsage:
keyCertSign
,
cRLSign
netscape-cert-type:
Object-signing CA
(required for Object
Signing)
subjectKeyIdentifier
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
Code
Signing (required for
Authenticode)
keyUsage:
keyCertSign
,
cRLSign
netscape-cert-type:
Object-signing CA
(required for Object
Signing)
subjectKeyIdentifier
authorityKeyIdentifier
cRLDistributionPoints
extKeyUsage:
Code Signing
(required for Authenticode)
keyUsage:
digitalSignature
netscape-cert-type:
Object-signing (required for
Object Signing)
subjectAltName
subjectKeyIdentifier
Table C-1
Recommendations for Use of Certificate Extensions with CMS (Continued)
Certificate type
CA root
Intermediate CA
Issued certificate
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...