Standard X.509 v3 Certificate Extensions
346
Netscape Certificate Management System Plug-Ins Guide • May 2002
CMS Version Support
Refer to “ExtendedKeyUsageExt Plug-in Module” on page 168.
•
CMS 4.1
: Not supported
•
CMS 4.2
: Supported
•
CMS 4.2-SP2
: Supported
•
CMS 4.5
: Supported
•
CMS 6.0
: Supported
Netscape Recommendations
Netscape recommends that this extension be supported for all certificates, and
requires it for all certificates that support step-up, or Server Gated Crypto (SGC).
OCSP Signing should be included in all certificates issued to OCSP responders.
Microsoft Recommendations
Microsoft products interpret this extension as follows. If the extension is not
present, the certificate is considered to be valid for any usage (to support backward
compatibility with certificates that did not use this extension). Otherwise,
interpretation depends on usage, as follows:
•
Authenticode requires that Code Signing be the unique usage specified.
•
SGC operation requires that the SGC usage be specified.
•
Timestamping requires that timestamping usage be specified.
Table C-3
Private Extended Key Usage Extension Uses
Use
OID
Certificate trust list signing
1.3.6.1.4.1.311.10.3.1
Microsoft Server Gated
Crypto (SGC)
1.3.6.1.4.1.311.10.3.3
Microsoft Encrypted File
System
1.3.6.1.4.1.311.10.3.4
Netscape SGC
2.16.840.1.113730.4.1
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...