Certificate Authority Decisions
172
Netscape Certificate Management System Installation and Setup Guide • March 2002
your root certificate into all the browsers used with the certificates you issue. If you
are using Netscape Communicator as your client, you can accomplish this task
within an intranet by using tools such as Mission Control Desktop or with the aid
of Personal Security Manager, but extranet deployments can be more complicated.
CAs and Certificate Extensions
An X.509 v3 certificate contains an extensions field that permits any number of
additional fields to be added to the certificate. Certificate extensions provide a way
of adding information such as alternative subject names, policy information, and
usage restrictions to certificates. The X.509 v3 standard defines a number of
extensions for various purposes. Certificate Management System provides policy
modules that you can use to set many of the standard extensions in the certificates
the server issues.
Before the X.509 v3 standard was finalized, Netscape and other companies had to
address certain issues, such as usage restrictions, with their own extension
definitions. Therefore, to maintain compatibility with older versions of browsers
that were released before the X.509 v3 specification was finalized, certain kinds of
certificates should include some of the Netscape extensions. Certificate
Management System provides policy modules that you can use to implement
essential Netscape extensions.
The Internet Engineering Task Force (IETF), which controls many of the standards
that underlie the Internet, is currently developing public-key infrastructure X.509
(PKIX) standards. These proposed standards further refine the X.509 v3 approach
to extensions for use on the Internet. PKIX working group recommendations
should also be taken into account when planning extensions for CA certificates,
subordinate CA certificates, and end-entity certificates.
For more detailed information about extensions and recommendations for specific
types of certificates, see Appendix C, “Certificate and CRL Extensions” of CMS
Plug-Ins Guide.
CA Certificate Renewal or Reissuance
When a CA signing certificate expires, all certificates signed with the CA’s
corresponding signing key become invalid. End entities use information in the CA
certificate to verify the certificate’s authenticity. If the CA certificate itself has
expired, applications cannot chain the certificate to a trusted CA.
There are two ways of dealing with CA certificate expiration:
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...