Standard X.509 v3 Certificate Extensions
Appendix
G
Certificate and CRL Extensions
727
extKeyUsage
OID
2.5.29.37
Criticality
If this extension is marked critical, the certificate must be used for one of the
indicated purposes only. If it is not marked critical, it is treated as an advisory field
that may be used to identify keys but does not restrict the use of the certificate to
the indicated purposes.
Discussion
The Extended Key Usage extension indicates one or more purposes for which the
certified public key may be used. These purposes may be in addition to or in place
of the basic purposes indicated in the key usage extension.
The Extended Key Usage extension must include OCSP Signing in an OCSP
responder’s certificate (unless the CA signing key that signed the certificates
validated by the responder is also the OCSP signing key). The OCSP responder’s
certificate must be issued directly by the CA that signs certificates the responder
will validate.
The Key Usage, Extended Key Usage, and Basic Constraints extensions act together
to define the purposes for which the certificate is intended to be used. Applications
can use these extensions to disallow the use of a certificate in inappropriate
contexts.
Table G-1 lists the uses defined by PKIX for this extension, and Table G-2 lists uses
privately defined by Microsoft or Netscape.
Table G-1
PKIX Extended Key Usage Extension Uses
Use
OID
Server authentication
1.3.6.1.5.5.7.3.1
Client authentication
1.3.6.1.5.5.7.3.2
Code signing
1.3.6.1.5.5.7.3.3
1.3.6.1.5.5.7.3.4
Timestamping
1.3.6.1.5.5.7.3.8
OCSP Signing
1.3.6.1.5.5.7.3.9*
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...