Chapter 13. Certificate Profiles
294
13.7.3. Basic Constraints Extension Default
This default attaches the Basic Constraint extension to the certificate. The extension identifies whether
the Certificate Manager is a CA. The extension is also used during the certificate chain verification
process to identify CA certificates and to apply certificate chain-path length constraints.
For general information about this extension, see
Section A.3.3, “basicConstraints”
.
The following constraints can be defined with this default:
• Basic Constraints Extension Constraint; see
Section 13.8.1, “Basic Constraints Extension
Constraint”
.
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
IsCA
Specifies whether the certificate subject is a CA. With
true
,
the server checks the
PathLen
parameter and sets the
specified path length in the certificate. With
false
, the server
treats the certificate subject as a non-CA and ignores the value
specified for the
PathLen
parameter.
PathLen
Specifies the path length, the maximum number of CA
certificates that may be chained below (subordinate to) the
subordinate CA certificate being issued. The path length
affects the number of CA certificates to be used during
certificate validation. The chain starts with the end-entity
certificate being validated and moves up.
The
maxPathLen
parameter has no effect if the extension is
set in end-entity certificates.
The permissible values are
0
or
n
. The value should be
less than the path length specified in the Basic Constraints
extension of the CA signing certificate.
0
specifies that no
subordinate CA certificates are allowed below the subordinate
CA certificate; only an end-entity certificate may follow in the
path.
n
must be an integer greater than zero. It specifies the
maximum number of subordinate CA certificates allowed below
the subordinate CA certificate.
If the field is blank, the path length defaults to a value that is
determined by the path length set in the Basic Constraints
extension in the issuer's certificate. If the issuer's path length
is unlimited, the path length in the subordinate CA certificate
will also be unlimited. If the issuer's path length is an integer
greater than zero, the path length in the subordinate CA
certificate will be set to a value that's one less than the issuer's
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...