subjectDirectoryAttributes
437
A.3.14.2. Criticality
If the certificate's subject field is empty, this extension must be marked critical.
A.3.14.3. Discussion
The Subject Alternative Name extension includes one or more alternative (non-X.500) names for
the identity bound by the CA to the certified public key. It may be used in addition to the certificate's
subject name or as a replacement for it. Defined name forms include Internet electronic mail address
(SMTP, as defined in RFC-822), DNS name, IP address, and uniform resource identifier (URI).
PKIX requires this extension for entities identified by name forms other than the X.500 distinguished
name (DN) used in the subject field. PKIX Part 1 describes additional rules for the relationship
between this extension and the subject field.
Email addresses may be provided in the Subject Alternative Name extension, the certificate subject
name field, or both. If the email address is part of the subject name, it must be in the form of the
EmailAddress
attribute defined by PKCS #9. Software that supports S/MIME must be able to read
an email address from either the Subject Alternative Name extension or from the subject name field.
A.3.15. subjectDirectoryAttributes
A.3.15.1. OID
2.5.29.9
A.3.15.2. Criticality
PKIX Part 1 requires that this extension be marked noncritical.
A.3.15.3. Discussion
The Subject Directory Attributes extension conveys any desired directory attribute values for the
subject of the certificate. It is not recommended as an essential part of the proposed PKIX standard
but may be used in local environments.
A.3.16. subjectKeyIdentifier
A.3.16.1. OID
2.5.29.14
A.3.16.2. Criticality
This extension is always noncritical.
A.3.16.3. Discussion
The Subject Key Identifier extension identifies the public key certified by this certificate. This extension
provides a way of distinguishing public keys if more than one is available for a given subject name.
The value of this extension should be calculated by performing a SHA-1 hash of the certificate's DER-
encoded
subjectPublicKey
, as recommended by PKIX. The Subject Key Identifier extension is
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...