Chapter 13. Certificate Profiles
298
The EFS recovery certificate is used by a recovery agent when a user loses the private key and the
data encrypted with that key needs to be used. Certificate System supports these two OIDs and allows
certificates to be issued containing the Extended Key Usage extension with these OIDs.
Normal user certificates should be created with only the EFS OID, not the recovery OID.
The following constraints can be defined with this default:
• Extended Key Usage Constraint; see
Section 13.8.2, “Extended Key Usage Extension Constraint”
.
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
OIDs
Specifies the OID that identifies a key-usage purpose. The
permissible values are a unique, valid OID specified in the
dot-separated numeric component notation. For example,
2.16.840.1.113730.1.99
. Depending on the key-usage
purposes, the OIDs can be designated by PKIX (listed in
Table 13.6, “PKIX Usage Definitions for the Extended Key
Usage Extension”
) or custom OIDs. Custom OIDs must be in
the registered subtree of IDs reserved for the company's use.
Although it is possible to use custom OIDs for evaluating and
testing the Certificate System, in a production environment,
comply with the ISO rules for defining OIDs and for registering
subtrees of IDs. See
Section A.2, “Note on Object Identifiers”
for information on allocating private OIDs.
Table 13.7. Extended Key Usage Extension Default Configuration Parameters
13.7.6. Freshest CRL Extension Default
This default attaches the Freshest CRL extension to the certificate.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
This default defines five locations with parameters for each location. The parameters are marked with
an
n
in the table to show with which location the parameter is associated.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
PointEnable_
n
Select
true
to enable this point; select
false
to disable this
point.
PointType_
n
Specifies the type of issuing point, either
DirectoryName
or
URIName
.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...