Extensions for CRLs
479
A.5.1.6. issuingDistributionPoint
A.5.1.6.1. OID
2.5.29.28
A.5.1.6.2. Criticality
PKIX requires that this extension be critical if it exists.
A.5.1.6.3. Discussion
The Issuing Distribution Point CRL extension identifies the CRL distribution point for a particular CRL
and indicates what kinds of revocation it covers, such as revocation of end-entity certificates only, CA
certificates only, or revoked certificates that have a limited set of reason codes.
PKIX Part I does not require this extension.
A.5.1.6.4. Parameters
Parameter
Description
enable
Sets whether the extension is enabled; the default is disabled.
critical
Marks the extension as critical, the default, or noncritical.
pointType
Specifies the type of the issuing distribution point from the
following:
•
directoryName
specifies that the type is an X.500
directory name.
•
URIName
specifies that the type is a uniform resource
indicator.
pointName
Gives the name of the issuing distribution point. The name of
the distribution point depends on the value specified for the
pointType
parameter.
• For
directoryName
, the name must be an X.500
name. For example,
cn=CRLCentral,ou=Research
Dept,o=Example Corporation,c=US
• For
URIName
, the name must be a URI that is an absolute
pathname and specifies the host. For example,
http://
testCA.example.com/get/crls/here/
.
NOTE
The CRL may be stored in the directory entry
corresponding to the CRL issuing point, which may
be different than the directory entry of the CA.
onlySomeReasons
Specifies the reason codes associated with the distribution
point.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...