Name Constraints Extension Default
435
Parameter
Description
used for CA certificates. Select
true
to set the
option.
cRLSign
Specifies whether to set the extension for CA
signing certificates that sign CRLs. Select
true
to set.
encipherOnly
Specifies whether to set the extension if the
public key is only for encrypting data while
performing key agreement. If this bit is set,
keyAgreement
should also be set. Select
true
to set.
decipherOnly
Specifies whether to set the extension if the
public key is only for decrypting data while
performing key agreement. If this bit is set,
keyAgreement
should also be set. Select
true
to set.
Table B.8. Key Usage Extension Default Configuration Parameters
B.1.9. Name Constraints Extension Default
This default attaches a Name Constraints extension to the certificate. The extension is used in CA
certificates to indicate a name space within which the subject names or subject alternative names in
subsequent certificates in a certificate chain should be located.
For general information about this extension, see
Section B.3.9, “nameConstraints”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section B.2.3, “Extension Constraint”
.
• No Constraints; see
Section B.2.6, “No Constraint”
.
This default defines up to five locations for both the permitted subtree and the excluded subtree and
sets parameters for each location. The parameters are marked with an
n
in the table to show with
which location the parameter is associated.
Parameter
Description
critical
Select
true
to mark this extension critical; select
false
to mark the extension noncritical.
PermittedSubtrees
n
.min
Specifies the minimum number of permitted
subtrees.
•
-1
specifies that the field should not be set in
the extension.
•
0
specifies that the minimum number of
subtrees is zero.
•
n
must be an integer that is greater than
zero. It sets the minimum required number of
subtrees.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...