Standard X.509 v3 Certificate Extensions
340
Netscape Certificate Management System Plug-Ins Guide • March 2002
OCSP signing certificates and CA signing certificates should only use the
authorityInfoAccess
extension to point to an OCSP responder if that responder
has been configured to verify them. For example, if there is a hierarchy of
responders, a subordinate responder may point to its parent for verification. If a
CA signing certificate points to an OCSP responder, that responder’s signing
certificate should be signed by a different CA (for example, the CA that issued the
CA signing certificate in question).
Microsoft Recommendation
Microsoft products do not currently use on-line revocation checking.
authorityKeyIdentifier
OID
2.5.29.35
Reference
http://www.ietf.org/rfc/rfc2459.txt
4.2.1.1
Criticality
This extension is always noncritical and is always evaluated.
Discussion
The Authority Key Identifier extension identifies the public key corresponding to
the private key used to sign a certificate. This extension is useful when an issuer
has multiple signing keys (for example, due to CA certificate renewal).
The extension consists of either or both of the following:
•
an explicit key identifier (
keyIdentifier
field)
•
an issuer (
authorityCertIssuer
field) and serial number
(
authorityCertSerialNumber
field) identifying a certificate
If the
keyIdentifier
field exists, then it is used to select the certificate with a
matching
subjectKeyIdentifier
extension. If the
authorityCertIssuer
and
authorityCertSerialNumber
fields are present, then they are used to identify the
correct certificate by
issuer
and
serialNumber
.
If this extension is not present, then the issuer name alone is used to identify the
issuer certificate.
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...