Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
462
OID
2.5.29.31
Criticality
PKIX recommends that this extension be marked noncritical and that it be supported for all certificates.
B.3.6. extKeyUsage
The Extended Key Usage extension indicates the purposes for which the certified public key may be
used. These purposes may be in addition to or in place of the basic purposes indicated in the Key
Usage extension.
The Extended Key Usage extension must include
OCSP Signing
in an OCSP responder's certificate
unless the CA signing key that signed the certificates validated by the responder is also the OCSP
signing key. The OCSP responder's certificate must be issued directly by the CA that signs certificates
the responder will validate.
The Key Usage, Extended Key Usage, and Basic Constraints extensions act together to define the
purposes for which the certificate is intended to be used. Applications can use these extensions to
disallow the use of a certificate in inappropriate contexts.
Table B.29, “PKIX Extended Key Usage Extension Uses”
lists the uses defined by PKIX for this
extension, and
Table B.30, “Private Extended Key Usage Extension Uses”
lists uses privately defined
by Netscape.
OID
2.5.29.37
Criticality
If this extension is marked critical, the certificate must be used for one of the indicated purposes only.
If it is not marked critical, it is treated as an advisory field that may be used to identify keys but does
not restrict the use of the certificate to the indicated purposes.
Use
OID
Server authentication
1.3.6.1.5.5.7.3.1
Client authentication
1.3.6.1.5.5.7.3.2
Code signing
1.3.6.1.5.5.7.3.3
1.3.6.1.5.5.7.3.4
Timestamping
1.3.6.1.5.5.7.3.8
OCSP Signing
1.3.6.1.5.5.7.3.9
1
OCSP Signing is not defined in PKIX Part 1, but in RFC 2560,
X.509 Internet Public Key Infrastructure Online Certificate Status
Protocol - OCSP
.
Table B.29. PKIX Extended Key Usage Extension Uses
Use
OID
Certificate trust list signing
1.3.6.1.4.1.311.10.3.1
Microsoft Server Gated Crypto (SGC)
1.3.6.1.4.1.311.10.3.3
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...