Defaults Reference
Chapter
10
Certificate Profiles
457
For general information about this extension, see “keyUsage” on page 728.
You can define the following constraints with this default:
•
Key Usage Constraint, see “Key Usage Extension Constraint,” on page 475.
•
Extension Constraint, see “Extension Constraint,” on page 475.
•
No Constraints, see “No Constraint,” on page 477.
Table 10-7
Key Usage Extension Default Configuration Parameters
Parameter
Description
critical
Select true to mark this extension critical; select false to mark the
extension noncritical.
digitalSignature
Specifies whether to allow for signing of SSL client certificates,
S/MIME signing certificates, and object-signing certificates.
Select
true
to set, select
false
to not set.
nonRepudiation
Specifies whether to some S/MIME signing certificates and
object-signing certificates. Note, however, that the use of this bit
is controversial. You should carefully consider the legal
consequences of its use before setting it for any certificate. Select
true
to set, select
false
to not set.
keyEncipherment
Specifies whether to set the extension for SSL server certificates
and S/MIME encryption certificates. Select
true
to set, select
false
to not set.
dataEncipherment
Specifies whether to set the extension when the subjects’s public
key is used to encipher user data (as opposed to key material).
Select
true
to set, select
false
to not set.
keyAgreement
Specifies whether to set the extension whenever the subject’s
public key is used for key agreement. Select
true
to set, select
false
to not set.
keyCertsign
Specifies whether extension for all CA signing certificates. Select
true
to set, select
false
to not set.
cRLSign
Specifies whether to set the extension for CA signing certificates
that are used to sign CRLs. Select
true
to set, select
false
to
not set.
encipherOnly
Specifies whether to set the extension if the public key is to be
used only for enciphering data. If this bit is set,
keyAgreement
should also be set. Select
true
to set, select
false
to not set.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...