Sample CRL and CRL Entry Extensions
439
The application receiving the CRL checks the extension ID to determine if it can recognize the ID. If it
can, it uses the extension ID to determine the type of value used.
A.4.2. Sample CRL and CRL Entry Extensions
The following is an example of the section of a CRL containing X.509 v2 extensions. The Certificate
System can display CRLs in readable pretty-print format, as shown here. As shown in the example,
CRL extensions appear in sequence and only one instance of a particular extension may appear per
CRL; for example, a CRL may contain only one Authority Key Identifier extension. However, CRL-entry
extensions appear in appropriate entries in the CRL.
Certificate Revocation List:
Data:
Version: v2
...
Extensions:
Identifier: Authority Key Identifier
Critical: no
Key Identifier:
2c:22:c6:ae:4e:4b:91:c7:fb:4c:cc:ae:84:e8:aa:5b:46:6a:a0:ad
Revoked Certificates:
Serial Number: 0x12
Revocation Date: Tuesday, December 15, 1998 5:20:42 AM
Extensions:
Identifier: Revocation Reason - 2.5.29.21
Critical: no
Reason: Key_Compromise
Serial Number: 0x11
Revocation Date: Wednesday, December 16, 1998 4:51:54 AM
Extensions:
Identifier: Revocation Reason - 2.5.29.21
Critical: no
Reason: CA_Compromise
Serial Number: 0x10
Revocation Date: Thursday, December 17, 1998 2:37:24 AM
Extensions:
Identifier: Revocation Reason - 2.5.29.21
Critical: no
Reason: Key_Compromise
Serial Number: 0xA
Revocation Date: Wednesday, November 25, 1998 5:11:18 AM
Extensions:
Identifier: Revocation Reason - 2.5.29.21
Critical: no
Reason: Affiliation_Changed
...
A.5. Standard X.509 v3 CRL Extensions
In addition to certificate extensions, the X.509 proposed standard defines extensions to CRLs, which
provide methods for associating additional attributes with Internet CRLs. These are one of two kinds:
extensions to the CRL itself and extensions to individual certificate entries in the CRL.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...