Chapter 13. Certificate Profiles
302
Parameter
Description
keyEncipherment
Specifies whether to set the extension for SSL server
certificates and S/MIME encryption certificates. Select
true
to
set.
dataEncipherment
Specifies whether to set the extension when the subject's
public key is used to encipher user data as opposed to key
material. Select
true
to set.
keyAgreement
Specifies whether to set the extension whenever the subject's
public key is used for key agreement. Select
true
to set.
keyCertsign
Specifies whether to use the extension for all CA signing
certificates. Select
true
to set.
cRLSign
Specifies whether to set the extension for CA signing
certificates that sign CRLs. Select
true
to set.
encipherOnly
Specifies whether to set the extension if the public key is only
for encrypting data. If this bit is set,
keyAgreement
should
also be set. Select
true
to set.
decipherOnly
Specifies whether to set the extension if the public key is only
for decrypting data. If this bit is set,
keyAgreement
should
also be set. Select
true
to set.
Table 13.10. Key Usage Extension Default Configuration Parameters
13.7.9. Name Constraints Extension Default
This default attaches a Name Constraints extension to the certificate. The extension is used in CA
certificates to indicate a name space within which the subject names or subject alternative names in
subsequent certificates in a certificate chain should be located.
For general information about this extension, see
Section A.3.9, “nameConstraints”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
This default defines up to five locations for both the permitted subtree and the excluded subtree and
sets parameters for each location. The parameters are marked with an
n
in the table to show with
which location the parameter is associated.
Parameter
Description
critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
PermittedSubtrees
n
.min
Specifies the minimum number of permitted subtrees.
•
-1
specifies that the field should not be set in the extension.
•
0
specifies that the minimum number of subtrees is zero.
•
n
must be an integer that is greater than zero. It sets the
minimum required number of subtrees.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...