
Introduction to CRL Extensions
Appendix
C
Certificate and CRL Extensions
359
❍
If the extension is not critical and the CRL is sent to an application that
does not understand the extension (based on the extension’s ID), the
application can ignore the extension and accept the CRL.
•
An octet string containing the DER encoding of the value of the extension.
Typically, the application receiving the CRL checks the extension ID to
determine if it can recognize the ID. If it can, it uses the extension ID to
determine the type of value used.
Sample CRL and CRL Entry Extensions
The following is an example of the section of a CRL containing X.509 v2 extensions.
(Certificate Management System can display CRLs in human-readable format, as
shown here.) As shown in the example, CRL extensions appear in sequence and
only one instance of a particular extension may appear in a particular CRL; for
example, a CRL may contain only one authority key identifier extension. However,
CRL-entry extensions appear in appropriate entries in the CRL.
Certificate Revocation List:
Data:
Version:
v2
...
Extensions:
Identifier: Authority Key Identifier
Critical: no
Key Identifier:
2c:22:c6:ae:4e:4b:91:c7:fb:4c:cc:ae:84:e8:aa:5b:46:6a:a0:ad
Extensions:
Identifier: Revocation Reason - 2.5.29.21
Critical: no
Reason: Key_Compromise
Serial Number: 0x12
Revocation Date: Tuesday, December 15, 1998 5:20:42 AM
Extensions:
Identifier: Revocation Reason - 2.5.29.21
Critical: no
Reason: CA_Compromise
Serial Number: 0x11
Revocation Date: Wednesday, December 16, 1998 4:51:54 AM
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...