CRL Distribution Points Extension Default
295
Parameter
Description
path length; for example, if the issuer's path length is 4, the
path length in the subordinate CA certificate will be set to 3.
Table 13.4. Basic Constraints Extension Default Configuration Parameters
13.7.4. CRL Distribution Points Extension Default
This default attaches the CRL Distribution Points extension to the certificate. This extension identifies
locations from which an application that is validating the certificate can obtain the CRL information to
verify the revocation status of the certificate.
For general information about this extension, see
Section A.3.5, “CRLDistributionPoints”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
This default defines up to five locations, with parameters for each location. The parameters are
marked with an
n
in the table to show with which location the parameter is associated.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
Type_
n
Specifies the type of CRL distribution point. The
permissible values are
DirectoryName
,
URIName
, or
RelativeToIssuer
. The type must correspond to the value
in the
Name
field.
Name_
n
Specifies the name of the CRL distribution point, the name can
be in any of the following formats:
• An X.500 directory name in the RFC 2253 syntax. The name
looks similar to the subject name in a certificate, like
cn=CA
Central, ou=Research Dept, o=Example Corporation, c=US
.
• A URIName, such as
http://testCA.example.com:80
.
• An RDN which specifies a location relative to the CRL
issuer. In this case, the value of the
Type
attribute must be
RelativeToIssuer
.
Reasons_
n
Specifies revocation reasons covered by the CRL maintained
at the distribution point. Provide a comma-separated list of the
following constants:
• unused
• keyCompromise
• cACompromise
• affiliationChanged
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...