Appendix A. Certificate and CRL Extensions
470
A.3.11.2. Criticality
This extension may be critical or noncritical.
A.3.11.3. Discussion
This extension, which is for CA certificates only, constrains path validation in two ways. It can be used
to prohibit policy mapping or to require that each certificate in a path contain an acceptable policy
identifier.
PKIX requires that, if present, this extension must never consist of a null sequence. At least one of the
two available fields must be present.
A.3.12. policyMappings
A.3.12.1. OID
2.5.29.33
A.3.12.2. Criticality
This extension must be noncritical.
A.3.12.3. Discussion
The Policy Mappings extension is used in CA certificates only. It lists one or more pairs of OIDs used
to indicate that the corresponding policies of one CA are equivalent to policies of another CA. It may
be useful in the context of cross-pair certificates.
This extension may be supported by CAs and applications.
A.3.13. privateKeyUsagePeriod
A.3.13.1. OID
2.5.29.16
A.3.13.2. Discussion
The Private Key Usage Period extension allows the certificate issuer to specify a different validity
period for the private key than for the certificate itself. This extension is intended for use with digital
signature keys.
NOTE
PKIX Part 1 recommends against the use of this extension. CAs conforming to PKIX Part
1
must not
generate certificates with this extension.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...