Recommendations for Certificate Extension Use
332
Netscape Certificate Management System Plug-Ins Guide • March 2002
cRLDistributionPoints.
Defines how CRL information for the certificate is to be
obtained.
extKeyUsage.
Indicates purpose or purposes for which the certificate may be used,
either in addition to or instead of the purposes indicated by the keyUsage
extension.
keyUsage.
Indicates the purpose or purposes for which the public key certified by
the certificate may be used.
netscape-cert-type.
Indicates the purpose or purposes for which the certificate may
be used. Required only for compatibility with some Netscape products that were
released before by X.509 v3 was finalized.
subjectAltName.
Specifies one or more alternative names for the identity bound by
the CA to the certified public key.
subjectKeyIdentifier.
Identifies the public key certified by the certificate.
These extensions, plus others, are described in detail in later sections of this
appendix. Additional extensions may be useful for a variety of purposes. However,
the extensions listed above are either required or recommended for various kinds
of certificates issued by Certificate Management System.
Table C-1 summarizes guidelines for using these extensions. The table provides a
summary only. Each extension is explained in detail later in the Appendix. Keep
the following in mind as you use the table:
•
Using certificate extensions incorrectly can lead to severe deployment
problems. Make sure you have thoroughly analyzed your deployment needs
and completely understand the purpose of each extension you want to use
before adding them to certificates.
•
Unless otherwise noted in Table C-1, the extensions indicated should be
included with certificates of each type to ensure compatibility with both PKIX
Part 1 and with future Netscape products.
•
Extensions marked “required” must be supported for some existing Netscape
or Microsoft products or for other reasons explained in the extenstion
descriptions that follow.
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...