
Appendix A. Certificate and CRL Extensions
444
Parameter
Description
For example,
CN=CACentral,OU=Research
Dept,O=Example Corporation,C=US
.
• For
dNSName
, the value must be a valid domain name in the
DNS format. For example,
testCA.example.com
.
• For
ediPartyName
, the name must be an IA5String. For
example,
Example Corporation
.
• For
URL
, the value must be a non-relative URI. For example,
http://testCA.example.com
.
• For
iPAddress
, the value must be a valid IP address
specified in dot-separated numeric component notation.
It can be the IP address or the IP address including the
netmask.
• For
OID
, the value must be a unique, valid OID specified
in the dot-separated numeric component notation. For
example,
1.2.3.4.55.6.5.99
. Although custom OIDs
can be used to evaluate and test the server, in a production
environment, comply with the ISO rules for defining OIDs
and for registering subtrees of IDs. See
Section A.2, “Note
on Object Identifiers”
for information on allocating private
OIDs.
• For
otherName
, the names can be any other format;
this supports
PrintableString
,
IA5String
,
UTF8String
,
BMPString
,
Any
, and
KerberosName
.
PrintableString
,
IA5String
,
UTF8String
,
BMPString
, and
Any
set a string to a base-64 encoded
file specifying the subtree, such as
/var/lib/rhpki-
ca/othername.txt
.
KerberosName
has the format
Realm|NameType|NameStrings
, such as
realm1|0|
userID1,userID2
.the name must be the absolute path
to the file that contains the general name in its base-64
encoded format. For example,
/var/lib/rhpki-ca/
extn/ian/othername.txt
.
Table A.8. IssuerAlternativeName Configuration Parameters
A.5.1.6. issuingDistributionPoint
A.5.1.6.1. OID
2.5.29.28
A.5.1.6.2. Criticality
PKIX requires that this extension be critical if it exists.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...