Chapter 12. Certificate Profiles
284
Parameter
Description
being set; select a hyphen,
-
, to indicate no constraints are
placed for this parameter.
WARNING
Using this bit is controversial. Carefully consider
the legal consequences of its use before setting it
for any certificate.
keyEncipherment
Specifies whether to set the extension for SSL server
certificates and S/MIME encryption certificates. Select
true
to
allow this to be set; select
false
to keep this from being set;
select a hyphen,
-
, to indicate no constraints are placed for
this parameter.
dataEncipherment
Specifies whether to set the extension when the subject's
public key is used to encrypt user data, instead of key material.
Select
true
to allow this to be set; select
false
to keep this
from being set; select a hyphen,
-
, to indicate no constraints
are placed for this parameter.
keyAgreement
Specifies whether to set the extension whenever the subject's
public key is used for key agreement. Select
true
to allow
this to be set; select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed for this
parameter.
keyCertsign
Specifies whether the extension applies for all CA signing
certificates. Select
true
to allow this to be set; select
false
to keep this from being set; select a hyphen,
-
, to indicate no
constraints are placed for this parameter.
cRLSign
Specifies whether to set the extension for CA signing
certificates that are used to sign CRLs. Select
true
to allow
this to be set; select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed for this
parameter.
encipherOnly
Specifies whether to set the extension if the public key is to be
used only for encrypting data. If this bit is set,
keyAgreement
should also be set. Select
true
to allow this to be set; select
false
to keep this from being set; select a hyphen,
-
, to
indicate no constraints are placed for this parameter.
decipherOnly
Specifies whether to set the extension if the public key
is to be used only for deciphering data. If this bit is set,
keyAgreement
should also be set. Select
true
to allow this
to be set; select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed for this
parameter.
Table 12.24. Key Usage Extension Constraint Configuration Parameters
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...