
Introduction to CRL Extensions
Appendix G
Certificate and CRL Extensions
741
subjectKeyIdentifier
OID
2.5.29.14
Criticality
This extension is always noncritical.
Discussion
The Subject Key Identifier extension identifies the public key certified by this certificate.
This extension provides a way of distinguishing public keys if more than one is available
for a given subject name, for example after the certificate has been renewed with a new key.
The value of this extension should be calculated by performing a SHA-1 hash of the
certificate’s DER-encoded
subjectPublicKey
, as recommended by PKIX. The Subject
Key Identifier extension is used in conjunction with the Authority Key Identifier extension
for CA certificates. If the CA certificate has a Subject Key Identifier extension, the key
identifier in the Authority Key Identifier extension (of the certificate being verified) should
match the key identifier of the CA’s Subject Key Identifier extension. It is not necessary for
the verifier to recompute the key identifier in this case.
PKIX Part 1 requires this extension for all CA certificates and recommends it for all other
certificates.
CS Version Support
Supported since CS 4.1. Refer to “SubjectKeyIdentifierExt” on page 540.
Introduction to CRL Extensions
Since its initial publication, the X.509 standard for CRL formats has been amended to
include additional information within a CRL. Version 2, the latest version, allows you to
add information as CRL extensions.
The extensions defined by ANSI X9 and ISO/IEC/ITU for X.509 v2 CRLs [X.509] [X9.55]
enable you to associate additional attributes with CRLs. The
Internet X.509 Public Key
Infrastructure Certificate and CRL Profile
(see
http://www.ietf.org/rfc/rfc2459.txt
) recommends a set of extensions to be used
in CRLs. These extensions are called
standard CRL extensions
.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...