Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
426
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to mark the extension noncritical.
IsCA
Specifies whether the certificate subject is a
CA. With
true
, the server checks the
PathLen
parameter and sets the specified path length in
the certificate. With
false
, the server treats the
certificate subject as a non-CA and ignores the
value specified for the
PathLen
parameter.
PathLen
Specifies the path length, the maximum number
of CA certificates that may be chained below
(subordinate to) the subordinate CA certificate
being issued. The path length affects the number
of CA certificates to be used during certificate
validation. The chain starts with the end-entity
certificate being validated and moves up.
The
maxPathLen
parameter has no effect if the
extension is set in end-entity certificates.
The permissible values are
0
or
n
. The value
should be less than the path length specified
in the Basic Constraints extension of the
CA signing certificate.
0
specifies that no
subordinate CA certificates are allowed below
the subordinate CA certificate; only an end-
entity certificate may follow in the path.
n
must
be an integer greater than zero. It specifies the
maximum number of subordinate CA certificates
allowed below the subordinate CA certificate.
If the field is blank, the path length defaults to
a value that is determined by the path length
set in the Basic Constraints extension in the
issuer's certificate. If the issuer's path length is
unlimited, the path length in the subordinate CA
certificate will also be unlimited. If the issuer's
path length is an integer greater than zero, the
path length in the subordinate CA certificate will
be set to a value that's one less than the issuer's
path length; for example, if the issuer's path
length is 4, the path length in the subordinate CA
certificate will be set to 3.
Table B.2. Basic Constraints Extension Default Configuration Parameters
B.1.4. CRL Distribution Points Extension Default
This default attaches the CRL Distribution Points extension to the certificate. This extension identifies
locations from which an application that is validating the certificate can obtain the CRL information to
verify the revocation status of the certificate.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...