717
Appendix
G
Certificate and CRL Extensions
This appendix explains both the standard certificate extensions defined by X.509 v3
and the extensions defined by Netscape that were used in versions of products
released before X.509 v3 was finalized. It also provides recommendations for
extensions to use with specific kinds of certificates, including both PKIX Part 1
recommendations and Netscape extensions that must be supported for
compatibility with early versions of Netscape products.
This appendix contains the following sections:
•
Introduction to Certificate Extensions
•
Standard X.509 v3 Certificate Extensions
•
Introduction to CRL Extensions
•
Standard X.509 v3 CRL Extensions
•
Netscape-Defined Certificate Extensions
•
CA Certificates and Extension Interactions
Introduction to Certificate Extensions
An X.509 v3 certificate contains an extensions field that permits any number of
additional fields to be added to the certificate. Certificate extensions provide a way
of adding information such as alternative subject names and usage restrictions to
certificates. Older versions of Netscape browsers and servers that were developed
before PKIX part 1 standards were defined require Netscape-specific extensions.
The X.509 v1 certificate specification was originally designed to bind public keys to
names in an X.500 directory. As certificates began to be used on the Internet and
extranets, and directory lookups could not always be performed, problem areas
such as the following emerged that were not foreseen in the original specification:
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...