subjectAltName
471
A.3.14. subjectAltName
A.3.14.1. OID
2.5.29.17
A.3.14.2. Criticality
If the certificate's subject field is empty, this extension must be marked critical.
A.3.14.3. Discussion
The Subject Alternative Name extension includes one or more alternative (non-X.500) names for
the identity bound by the CA to the certified public key. It may be used in addition to the certificate's
subject name or as a replacement for it. Defined name forms include Internet electronic mail address
(SMTP, as defined in RFC-822), DNS name, IP address, and uniform resource identifier (URI).
PKIX requires this extension for entities identified by name forms other than the X.500 distinguished
name (DN) used in the subject field. PKIX Part 1 describes additional rules for the relationship
between this extension and the subject field.
Email addresses may be provided in the Subject Alternative Name extension, the certificate subject
name field, or both. If the email address is part of the subject name, it must be in the form of the
EmailAddress
attribute defined by PKCS #9. Software that supports S/MIME must be able to read
an email address from either the Subject Alternative Name extension or from the subject name field.
A.3.15. subjectDirectoryAttributes
A.3.15.1. OID
2.5.29.9
A.3.15.2. Criticality
PKIX Part 1 requires that this extension be marked noncritical.
A.3.15.3. Discussion
The Subject Directory Attributes extension conveys any desired directory attribute values for the
subject of the certificate. It is not recommended as an essential part of the proposed PKIX standard
but may be used in local environments.
A.3.16. subjectKeyIdentifier
A.3.16.1. OID
2.5.29.14
A.3.16.2. Criticality
This extension is always noncritical.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...