
Standard X.509 v3 Certificate Extensions
Appendix G
Certificate and CRL Extensions
731
CS (CS) version support is listed for each extension. “Supported” means that the indicated
version of CS ships with built-in support for the extension via a policy plug-in. “Not
supported” means that the indicated version of CS does not ship a policy plug-in for the
extension (although the extension can be used if a custom plug-in is written).
authorityInfoAccess
OID
1.3.6.1.5.5.7.1.1
Criticality
This extension must be noncritical.
Discussion
The Authority Information Access extension indicates how and where to access information
about the issuer of the certificate. The extension contains an
accessMethod
and an
accessLocation
field. The
accessMethod
specifies (by an OID) the type and format of
information about the issuer found at the
accessLocation
.
PKIX Part 1 defines one
accessMethod
(
id-ad-caIssuers
) to get a list of CAs that
have issued certificates higher in the CA chain than the issuer of the certificate using the
extension. The
accessLocation
field then typically contains a URL indicating the
location and protocol (LDAP, HTTP, FTP) used to retrieve the list.
The Online Certificate Status Protocol (RFC 2560), available at
http://www.ietf.org/rfc/rfc2560.txt
, defines an
accessMethod
(
id-ad-ocsp
)
for using OCSP to verify certificates. The
accessLocation
field then contains a URL
indicating the location and protocol used to access an OCSP responder that can validate the
certificate.
CS Version Support
Supported since version 4.2. Refer to “AuthInfoAccessExt” on page 489.
authorityKeyIdentifier
OID
2.5.29.35
Criticality
This extension is always noncritical and is always evaluated.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...