![Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Скачать руководство пользователя страница 496](http://html.mh-extra.com/html/red-hat/certificate-system-7-3-administration/certificate-system-7-3-administration_administration-manual_1427433496.webp)
Appendix A. Certificate and CRL Extensions
474
A.5. Standard X.509 v3 CRL Extensions
In addition to certificate extensions, the X.509 proposed standard defines extensions to CRLs, which
provide methods for associating additional attributes with Internet CRLs. These are one of two kinds:
extensions to the CRL itself and extensions to individual certificate entries in the CRL.
•
Section A.5.1, “Extensions for CRLs”
•
Section A.5.2, “CRL Entry Extensions”
A.5.1. Extensions for CRLs
The following CRL descriptions are defined as part of the Internet X.509 v3 Public Key Infrastructure
proposed standard.
•
Section A.5.1.1, “authorityKeyIdentifier”
•
Section A.5.1.2, “CRLNumber”
•
Section A.5.1.3, “deltaCRLIndicator”
•
Section A.5.1.5, “issuerAltName”
•
Section A.5.1.6, “issuingDistributionPoint”
A.5.1.1. authorityKeyIdentifier
A.5.1.1.1. OID
2.5.29.35
A.5.1.1.2. Discussion
The Authority Key Identifier extension for a CRL identifies the public key corresponding to the private
key used to sign the CRL. For details, see the discussion under certificate extensions at
Section A.3.2,
“The authorityKeyIdentifier”
.
The PKIX standard recommends that the CA must include this extension in all CRLs it issues because
a CA's public key can change, for example, when the key gets updated, or the CA may have multiple
signing keys because of multiple concurrent key pairs or key changeover. In these cases, the CA ends
up with more than one key pair. When verifying a signature on a certificate, other applications need to
know which key was used in the signature.
A.5.1.1.3. Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. The default
is to have this extension disabled.
critical
Sets whether the extension is marked as critical; the default is
noncritical.
Table A.4. AuthorityKeyIdentifierExt Configuration Parameters
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...