
Standard X.509 v3 Certificate Extensions
732
Red Hat Certificate System Administrator’s Guide • September 2005
Discussion
The Authority Key Identifier extension identifies the public key corresponding to the
private key used to sign a certificate. This extension is useful when an issuer has multiple
signing keys (for example, due to CA certificate renewal).
The extension consists of either or both of the following:
•
an explicit key identifier (
keyIdentifier
field)
•
an issuer (
authorityCertIssuer
field) and serial number
(
authorityCertSerialNumber
field) identifying a certificate
If the
keyIdentifier
field exists, then it is used to select the certificate with a matching
subjectKeyIdentifier
extension. If the
authorityCertIssuer
and
authorityCertSerialNumber
fields are present, then they are used to identify the
correct certificate by
issuer
and
serialNumber
.
If this extension is not present, then the issuer name alone is used to identify the issuer
certificate.
PKIX Part 1 requires this extension for all certificates except self-signed root CA
certificates. Where a key identifier has not been previously established, PKIX recommends
that the
authorityCertIssuer
and
authorityCertSerialNumber
fields be specified.
These fields permit construction of a complete certificate chain by matching the
SubjectName
and
CertificateSerialNumber
fields in the issuer’s certificate against
the
authortiyCertIssuer
and
authorityCertSerialNumber
in the
AuthorityKeyIdentifier
extension of the subject certificate.
CS Version Support
Supported since CS 4.1. Refer to “AuthorityKeyIdentifierExt” on page 492.
Note that CS does not use or support the
authorityCertSerialNumber
field in the
Authority Key Identifier extension.
basicConstraints
OID
2.5.29.19
Criticality
PKIX Part 1 requires that this extension be marked critical. This extension is evaluated
regardless of its criticality.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...