Chapter 13. Certificate Profiles
292
13.7. Defaults Reference
Defaults are used to define the contents of a certificate. This section lists and defines the predefined
defaults.
13.7.1. Authority Info Access Extension Default
This default attaches the Authority Info Access extension. This extension specifies how an application
validating a certificate can access information, such as online validation services and CA statements,
about the CA that has issued the certificate. This extension should not be used to point directly to
the CRL location maintained by a CA; the CRL Distribution Points extension,
Section 13.7.4, “CRL
Distribution Points Extension Default”
, provides references to CRL locations.
For general information about this extension, see
Section A.3.1, “authorityInfoAccess”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
This default can define up to five locations, with parameters for each location. The parameters are
marked with an
n
in the table to show with which location the parameter is associated.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
Method_
n
Specifies the access method for retrieving additional
information about the CA that has issued the certificate in
which the extension appears. This is one of the following
values:
• ocsp (1.3.6.1.5.5.7.48.1).
• caIssuers (1.3.6.1.5.5.7.48.2)
• renewal (2.16.840.1.113730.16.1)
LocationType_
n
Specifies the general name type for the location that contains
additional information about the CA that has issued the
certificate. This is one of the following types:
• DirectoryName
• DNSName
• EDIPartyName
• IPAddress
• OID
• RFC822Name
• URIName
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...