Appendix A. Certificate and CRL Extensions
440
•
Section A.5.1, “Extensions for CRLs”
•
Section A.5.2, “CRL Entry Extensions”
A.5.1. Extensions for CRLs
The following CRL descriptions are defined as part of the Internet X.509 v3 Public Key Infrastructure
proposed standard.
•
Section A.5.1.1, “authorityKeyIdentifier”
•
Section A.5.1.2, “CRLNumber”
•
Section A.5.1.3, “deltaCRLIndicator”
•
Section A.5.1.5, “issuerAltName”
•
Section A.5.1.6, “issuingDistributionPoint”
A.5.1.1. authorityKeyIdentifier
A.5.1.1.1. OID
2.5.29.35
A.5.1.1.2. Discussion
The Authority Key Identifier extension for a CRL identifies the public key corresponding to the private
key used to sign the CRL. For details, see the discussion under certificate extensions at
Section A.3.2,
“The authorityKeyIdentifier”
.
The PKIX standard recommends that the CA must include this extension in all CRLs it issues because
a CA's public key can change, for example, when the key gets updated, or the CA may have multiple
signing keys because of multiple concurrent key pairs or key changeover. In these cases, the CA ends
up with more than one key pair. When verifying a signature on a certificate, other applications need to
know which key was used in the signature.
A.5.1.1.3. Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. The default
is to have this extension disabled.
critical
Sets whether the extension is marked as critical; the default is
noncritical.
Table A.4. AuthorityKeyIdentifierExt Configuration Parameters
A.5.1.2. CRLNumber
A.5.1.2.1. OID
2.5.29.20
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...