Chapter 12. Certificate Profiles
282
Parameter
Description
range
Specifies the validity period for this certificate.
Table 12.20. Validity Default Configuration Parameters
12.8. Constraints Reference
Constraints are used to define the allowable contents of a certificate and the values associated with
that content. This section lists the predefined constraints with complete definitions of each.
12.8.1. Basic Constraints Extension Constraint
The Basic Constraints extension constraint checks if the basic constraint in the certificate request
satisfies the criteria set in this constraint.
Parameter
Description
Critical
Specifies whether the extension can be marked critical or
noncritical. Select
true
to allow this extension to be mark
critical; select
false
to prevent this extension from being
marked critical.
IsCA
Specifies whether the certificate subject is a CA. Select
true
to allow a value of
true
for this parameter; select
false
to
disallow a value of
true
for this parameter; select a hyphen,
-
,
to indicate no constraints are placed for this parameter.
PathLen
Specifies the maximum allowable path length, the maximum
number of CA certificates that may be chained below
(subordinate to) the subordinate CA certificate being issued.
The path length affects the number of CA certificates used
during certificate validation. The chain starts with the end-entity
certificate being validated and moves up.
This parameter has no effect if the extension is set in end-
entity certificates.
The permissible values are
0
or
n
. The value must be less than
the path length specified in the Basic Constraints extension of
the CA signing certificate.
0
specifies that no subordinate CA certificates are allowed
below the subordinate CA certificate being issued; only an end-
entity certificate may follow in the path.
n
must be an integer greater than zero. This is the maximum
number of subordinate CA certificates allowed below the
subordinate CA certificate being used.
If the field is blank, the path length defaults to a value
determined by the path length set on the Basic Constraints
extension in the issuer's certificate. If the issuer's path length
is unlimited, the path length in the subordinate CA certificate is
also unlimited. If the issuer's path length is an integer greater
than zero, the path length in the subordinate CA certificate
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...