
Extended Key Usage Extension Constraint
283
Parameter
Description
is set to a value one less than the issuer's path length; for
example, if the issuer's path length is 4, the path length in the
subordinate CA certificate is set to 3.
Table 12.21. Basic Constraints Extension Constraint Configuration Parameters
12.8.2. Extended Key Usage Extension Constraint
The Extended Key Usage extension constraint checks if the Extended Key Usage extension on the
certificate satisfies the criteria set in this constraint.
Parameter
Description
Critical
Specifies whether the extension can be marked critical or
noncritical. Select
true
to mark the extension critical; select
false
to mark it noncritical.
exKeyUsageOIDs
Specifies the allowable OIDs that identifies a key-usage
purpose. Multiple OIDs can be added in a comma-separated
list.
Table 12.22. Extended Key Usage Extension Constraint Configuration Parameters
12.8.3. Extension Constraint
This constraint implements the general extension constraint. It checks if the extension is present.
12.8.4. Key Constraint
This constraint checks the key length.
Parameter
Description
keyType
Gives a key type; this is set to
-
by default and uses an RSA
key system.
keyMinLength
Specifies the minimum allowable key length.
keyMaxLength
Specifies the maximum allowable key length.
Table 12.23. Key Constraint Configuration Parameters
12.8.5. Key Usage Extension Constraint
The Key Usage extension constraint checks if the key usage constraint in the certificate request
satisfies the criteria set in this constraint.
Parameter
Description
critical
Select
true
to mark this as critical; select
false
to mark it
noncritical.
digitalSignature
Specifies whether to sign SSL client certificates and S/MIME
signing certificates. Select
true
to allow this to be set; select
false
to keep this from being set; select a hyphen,
-
, to
indicate no constraints are placed for this parameter.
nonRepudiation
Specifies whether to set S/MIME signing certificates. Select
true
to allow this to be set; select
false
to keep this from
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...